Method of achieving high reliability of network boot computer system
Summary by NHIP
Network Fault Recovery Method
The method detects a fault in a server, network, or external disk device within a multi-server system. It then identifies an alternative server to access a replacement disk containing identical data and transmits a boot instruction to that server via the management network.
Claim Score by NHIP
Abstract
In a network computer system, recovery may be impossible from a fault when the fault occurs in a network switch in a network or a device such as an external disk device. Provided is a computer system that includes a plurality of servers, a plurality of networks, a plurality of external disk devices, and a management computer, in which the management computer detects a fault which is occurred, retrieves an application stop server inaccessible to the used disk due to the fault, retrieves the disk for storing the same contents as contents stored in the disk used by the retrieved application stop server and the external disk device including the disk, retrieves an application resuming server capable of accessing the retrieved external disk device, and transmits an instruction to boot by using the retrieved disk to the retrieved application resuming server.

Term
Projected expiry 10 November 2027.
- Priority
- Filed
- Granted
- Today
- Projected expiry
14 claims: 3 independent, 11 dependent
- 1A method of controlling a computer system including a plurality of servers, a plurality of networks connected to the plurality of servers, a plurality of external disk devices connected to the plurality of networks, and a management computer connected to the plurality of servers, the plurality of networks, and the plurality of external disk devices via a management network, each of the external disk devices including at least one disk for storing data, and the management computer including an interface connected to the management network, a first processor connected to the interface, and a first memory connected to the first processor, the method comprising:detecting, by the first processor, a fault which is occurred in any of the server, the network, and the external disk device;retrieving, by the first processor, an application stop server inaccessible to the used disk due to the fault among the plurality of servers;retrieving, by the first processor, a disk for storing the same contents as contents stored in the disk used by the retrieved application stop server among the plurality of disks, and the external disk device including the retrieved disk;retrieving, by the first processor, an application resuming server capable of accessing the retrieved external disk device via the network in which the fault is not occurred among the plurality of servers;and transmitting, by the first processor, an instruction to boot by using the retrieved disk to the retrieved application resuming server via the management network.
- 11A program for controlling a management computer in a computer system including a plurality of servers, a plurality of networks connected to the plurality of servers, a plurality of external disk devices connected to the plurality of networks, and a management computer connected to the plurality of servers, the plurality of networks, and the plurality of external disk devices via a management network, each of the external disk devices including at least one disk for storing data, and the management computer including an interface connected to the management network, a processor connected to the interface, and a memory connected to the processor to store the program, the program causing the processor to execute:a first step of detecting a fault which is occurred in any of the server, the network, and the external disk device;a second step of retrieving an application stop server inaccessible to the used disk due to the fault among the plurality of servers;a third step of retrieving a disk for storing the same contents as contents stored in the disk used by the retrieved application stop server among the plurality of disks, and the external disk device including the retrieved disk;a fourth step of retrieving an application resuming server capable of accessing the retrieved external disk device via the network in which the fault is not occurred among the plurality of servers;and a fifth step of transmitting an instruction to boot by using the retrieved disk to the retrieved application resuming server via the management network.
- 13Broadest claimClaim Score 46, average(NHIP)A computer system, comprising:a plurality of servers;a plurality of networks connected to the plurality of servers;a plurality of external disk devices connected to the plurality of networks;and a management computer connected to the plurality of servers, the plurality of networks, and the plurality of external disk devices via a management network, wherein: each of the external disk devices includes at least one disk for storing data;the management computer includes an interface connected to the management network, a processor connected to the interface, and a memory connected to the processor;the processor detects a fault which is occurred in any of the server, the network, and the external disk device;the processor retrieves an application stop server inaccessible to the used disk due to the fault among the plurality of servers;the processor retrieves a disk for storing the same contents as contents stored in the disk used by the retrieved application stop server among the plurality of disks, and the external disk device including the retrieved disk;the processor retrieves an application resuming server capable of accessing the retrieved external disk device via the network in which the fault is not occurred among the plurality of servers;and the processor transmits an instruction to boot by using the retrieved disk to the retrieved application resuming server via the management network.
Independent claims3
362 paragraphs in 5 sections, as filed
CLAIM OF PRIORITY
p-0002The present application claims priority from Japanese patent application P2006-117822 filed on Apr. 21, 2006, the content of which is hereby incorporated by reference into this application.
BACKGROUND OF THE INVENTION
p-0003This invention relates to a method of recovering an application when a fault occurs in a device included in a network boot server computer system.
p-0004There is made available a network boot computer system in which each server boots by reading a program of an operating system (OS) or the like from a disk of an external disk device in an environment having a plurality of servers connected to the external disk device via a network. In the network boot computer system, the plurality of servers are connected to the external disk device via the network and a network switch. Thus, a boot disk referred to by a certain server can be referred to by another server.
p-0005Regarding the network boot computer system, a fault recovery method of taking over an application of a faulted server to another server has been disclosed. To be specific, when a fault occurs in the server being operated, another server not being operated uses a boot disk of the external disk device used by the server to be booted. As a result, the application of the faulted server is taken over by another server (e.g., JP 2002-215474 A and JP 2000-47894 A).
SUMMARY OF THE INVENTION
p-0006According to the fault recovery method, recovery can be made from a fault when the fault occurs in the server. However, when a fault occurs in the external disk device including the boot disk or in the network switch present in the network for interconnecting the server and the disk, fault recovery by the method is impossible. For example, in a case where the server engaged in an application and the server not engaged in an application are connected to the same network switch or external disk device, when a fault occurs in the network switch or the external disk device, neither of the servers can continue the application, causing both of the servers to go down together.
p-0007Thus, in the conventional network boot computer system, when a fault occurs in the network switch in the network or the external disk device, the server that should take over the boot disk may not be able to access the boot disk. In this case, the server cannot take over the application to recover from the fault.
p-0008This invention has been made to solve the foregoing problems, and it is an object of this invention to continue an application by recovering from a fault occurring in a network switch present in a network path or a device such as an external disk device in a network boot computer system.
p-0009According to a representative aspect of this invention, there is provided a method of controlling a computer system including a plurality of servers, a plurality of networks connected to the plurality of servers, a plurality of external disk devices connected to the plurality of networks, and a management computer connected to the plurality of servers, the plurality of networks, and the plurality of external disk devices via a management network, in which each of the external disk devices includes at least one disk for storing data, the management computer includes an interface connected to the management network, a first processor connected to the interface, and a first memory connected to the first processor. The method includes: detecting, by the first processor, an occurrence of a fault in any of the server, the network, and the external disk device; retrieving, by the first processor, an application stop server inaccessible to the used disk due to the fault among the plurality of servers; retrieving, by the first processor, a disk for storing the same contents as contents of the disk used by the retrieved application stop server among the plurality of disks, and the external disk device including the retrieved disk; retrieving, by the first processor, an application resuming server capable of accessing the retrieved external disk device via the network in which the fault is not occurred among the plurality of servers; and transmitting, by the first processor, an instruction of booting by using the retrieved disk to boot to the retrieved application resuming server via the management network.
p-0010According to one embodiment of this invention, in the network boot computer system, even when a fault occurs in the network switch present in the network path or the device such as the external disk device used by the server to boot, a server accessible to the boot disk through the network is always present in the network boot computer system. Then, the server takes over the boot disk to boot, making it possible to recover the application. Processing for recovering the application is automatically executed by the management computer, and a work load on the system manager can thus be reduced.
BRIEF DESCRIPTION OF THE DRAWINGS
p-0011The present invention can be appreciated by the description which follows in conjunction with the following figures, wherein:
p-0012<figref idrefs="DRAWINGS">FIG. 1</figref> is a block diagram showing a configuration of a computer system according to a first embodiment of this invention;
p-0013<figref idrefs="DRAWINGS">FIG. 2</figref> is a block diagram showing a configuration of a server in detail according to the first embodiment of this invention;
p-0014<figref idrefs="DRAWINGS">FIG. 3</figref> is an explanatory diagram showing a fault recovery program and a boot path redundancy program in detail according to the first embodiment of this invention;
p-0015<figref idrefs="DRAWINGS">FIG. 4</figref> is an explanatory diagram showing a server information table according to the first embodiment of this invention;
p-0016<figref idrefs="DRAWINGS">FIG. 5</figref> is an explanatory diagram showing an external disk device information table according to the first embodiment of this invention;
p-0017<figref idrefs="DRAWINGS">FIG. 6</figref> is an explanatory diagram showing a redundant path information table according to the first embodiment of this invention;
p-0018<figref idrefs="DRAWINGS">FIG. 7</figref> is an explanatory diagram showing a logical disk management program provided in the external disk device according to the first embodiment of the this invention;
p-0019<figref idrefs="DRAWINGS">FIG. 8</figref> is an explanatory diagram showing a logical disk table according to the first embodiment of this invention;
p-0020<figref idrefs="DRAWINGS">FIG. 9</figref> is an explanatory diagram showing a disk synchronous program provided in the external disk device according to the first embodiment of this invention;
p-0021<figref idrefs="DRAWINGS">FIG. 10</figref> is an explanatory diagram showing a synchronous disk table according to the first embodiment of this invention;
p-0022<figref idrefs="DRAWINGS">FIG. 11</figref> is an explanatory diagram showing a security control program provided in the external disk device according to the first embodiment of the this invention;
p-0023<figref idrefs="DRAWINGS">FIG. 12</figref> is an explanatory diagram showing a disk mapping table according to the first embodiment of this invention;
p-0024<figref idrefs="DRAWINGS">FIG. 13</figref> is an explanatory diagram showing an application sequence executed by each device according to the first embodiment of this invention;
p-0025<figref idrefs="DRAWINGS">FIG. 14</figref> is a flowchart showing redundancy of a boot path executed by the boot path redundancy program according to the first embodiment of this invention;
p-0026<figref idrefs="DRAWINGS">FIG. 15</figref> is a flowchart showing fault monitoring executed by the fault recovery program according to the first embodiment of this invention;
p-0027<figref idrefs="DRAWINGS">FIG. 16</figref> is a flowchart showing application stop server retrieval and server power control executed by the fault recovery program according to the first embodiment of this invention;
p-0028<figref idrefs="DRAWINGS">FIG. 17</figref> is a flowchart showing application resuming server retrieval executed by the fault recovery program according to the first embodiment of this invention;
p-0029<figref idrefs="DRAWINGS">FIG. 18</figref> is a flowchart showing the application resuming server retrieval executed by the fault recovery program in detail according to the first embodiment of this invention;
p-0030<figref idrefs="DRAWINGS">FIG. 19</figref> is a flowchart showing network security control executed by the boot path redundancy program according to the first embodiment of this invention;
p-0031<figref idrefs="DRAWINGS">FIG. 20</figref> is a flowchart showing boot setting change and server power control executed by the fault recovery program according to the first embodiment of the this invention;
p-0032<figref idrefs="DRAWINGS">FIG. 21</figref> is an explanatory diagram showing mirroring executed according to a second embodiment of this invention;
p-0033<figref idrefs="DRAWINGS">FIG. 22</figref> is a flowchart showing redundancy of a boot path executed by a boot path redundancy program according to the second embodiment of this invention;
p-0034<figref idrefs="DRAWINGS">FIG. 23</figref> is an explanatory diagram showing creation of a synchronous disk executed according to a third embodiment of this invention;
p-0035<figref idrefs="DRAWINGS">FIG. 24</figref> is a flowchart showing redundancy of a boot path executed by a boot path redundancy program according to the third embodiment of this invention;
p-0036<figref idrefs="DRAWINGS">FIG. 25</figref> is an explanatory diagram showing a server information table according to a fourth embodiment of this invention;
p-0037<figref idrefs="DRAWINGS">FIG. 26</figref> is an explanatory diagram showing an external disk device information table according to the fourth embodiment of this invention;
p-0038<figref idrefs="DRAWINGS">FIG. 27</figref> is an explanatory diagram showing security control executed by NW-SW according to the fourth embodiment of this invention;
p-0039<figref idrefs="DRAWINGS">FIG. 28</figref> is an explanatory diagram showing a security table according to the fourth embodiment of this invention;
p-0040<figref idrefs="DRAWINGS">FIG. 29</figref> is a flowchart showing network security control executed by a boot path redundancy program according to the fourth embodiment of this invention;
p-0041<figref idrefs="DRAWINGS">FIG. 30</figref> is an explanatory diagram showing a fault recovery program and a boot path redundancy program in detail according to a fifth embodiment of this invention;
p-0042<figref idrefs="DRAWINGS">FIG. 31</figref> is a flowchart showing application resuming server retrieval executed by the fault recovery program according to the fifth embodiment of this invention;
p-0043<figref idrefs="DRAWINGS">FIG. 32</figref> is a flowchart showing network security control executed by the boot path redundancy program according to the fifth embodiment of this invention; and
p-0044<figref idrefs="DRAWINGS">FIG. 33</figref> is a block diagram showing a configuration of a management server in detail according to the first embodiment of this invention.
DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
p-0045The preferred embodiments of this invention will be described below with reference to the drawings.
p-0046<figref idrefs="DRAWINGS">FIG. 1</figref> is a block diagram showing a configuration of a computer system according to a first embodiment of this invention.
p-0047The computer system of this embodiment includes a management server <b>101</b>, a plurality of servers <b>102</b>, a plurality of external disk devices <b>103</b>, a plurality of network switches (NW-SW) <b>104</b>, and a management network switch (management NW-SW) <b>105</b>.
p-0048Each server <b>102</b> includes a network interface card (NIC) <b>121</b> connected to the management NW-SW <b>105</b>, and a network adaptor (referred to as adaptor) <b>120</b> connected to the NW-SW <b>104</b>.
p-0049The NW-SW <b>104</b> constitutes a network for interconnecting the server <b>102</b> and the external disk device <b>103</b>. The NW-SW <b>104</b> may be a switch for handling Ethernet protocol, a switch of a fibre channel, or a network switch of another kind.
p-0050The management NW-SW <b>105</b> constitutes a network for interconnecting the management server <b>101</b>, the server <b>102</b>, the external disk device <b>103</b>, and the NW-SW <b>104</b>. As in the case of the NW-SW <b>104</b>, the management NW-SW <b>105</b> may be a switch for handling Ethernet protocol, a switch of a fibre channel, or a network switch of another kind.
p-0051The NW-SW <b>104</b> is connected to a port (not shown) disposed in a controller <b>130</b> of the external disk device <b>103</b>. In an example of <figref idrefs="DRAWINGS">FIG. 1</figref>, one port of each controller <b>130</b> is connected to the NW-SW <b>104</b>. However, a plurality of ports of each controller <b>130</b> may be connected to the NW-SW <b>104</b>. Alternatively, the adaptor <b>120</b> of the server <b>102</b> may be directly connected to the controller <b>130</b> without using the NW-SW <b>104</b>.
p-0052The external disk device <b>103</b> includes one or more disks <b>131</b>. The server <b>102</b> can access a disk <b>131</b> via the NW-SW <b>104</b> and the controller <b>130</b>. The external disk device <b>103</b> may be, for example, a disk array device, a server for handling a network file system, or a server for handling iSCSI.
p-0053The controller <b>130</b> includes an information processor such as a CPU to control information input/output to/from the controller <b>130</b> and information recorded in the disk <b>131</b> in the external disk device <b>103</b>. The external disk device <b>103</b> can include a plurality of controllers <b>130</b>, and a certain controller <b>130</b> can operate without being affected by a fault of another controller <b>130</b>. The disk <b>131</b> is an information storage device accessible from the serer <b>102</b> to read/write data.
p-0054The disk <b>131</b> is a storage volume (so-called logical volume) logically recognized as one information storage device. One disk <b>131</b> may be constituted of one physical disk drive or a plurality of physical disk drives. Alternatively, the disk <b>131</b> may be constituted of an information storage device (e.g., semiconductor storage device) other than the disk drive. The disk <b>131</b> may have a so-called RAID configuration.
p-0055The disk <b>131</b> records a program of an operating system (OS), an application, middleware, a driver or the like used by the server <b>102</b>, and data, information of log, or the like used by the program. Data recorded in the disk <b>131</b> as described above will be referred to as a disk image hereinafter. In other words, the disk image indicates contents of the disk <b>131</b>. In <figref idrefs="DRAWINGS">FIG. 1</figref>, the disk image is shown by a disk image identifier of D<b>0</b>, D<b>1</b>, or the like. When contents of a plurality of disks <b>131</b> are identical, disk images recorded in the disks <b>131</b> have identical disk image identifiers.
p-0056For example, when there are two disks <b>131</b> recording disk images whose identifiers are “D<b>0</b>”, entire contents of the disks <b>131</b> are identical. In other words, data stored in one of the two disks <b>131</b> is always stored in the other disk <b>131</b>.
p-0057The management NW-SW <b>105</b> is connected to a management server <b>101</b> for managing the computer system, a NIC <b>121</b> of the server <b>102</b>, a management port (not shown) disposed in a controller <b>140</b> of the NW-SW <b>104</b>, and a management port (not shown) disposed in the controller <b>130</b> of the external disk device <b>103</b>. The controller <b>130</b> of the external disk device <b>103</b> can receive control of the external disk device <b>103</b> from the management server <b>101</b> via the management port. The controller <b>130</b> can notify a fault occurrence of the external disk device <b>103</b> to the management server <b>101</b> via the management port. The management port of the controller <b>140</b> of the NW-SW <b>104</b> can receive control of the NW-SW <b>104</b> from the management server <b>101</b>. Additionally, the management port of the controller <b>140</b> can notify a fault occurrence of the NW-SW <b>104</b> to the management server <b>101</b>.
p-0058The management server <b>101</b> includes a fault recovery program <b>110</b> and a boot path redundancy program <b>111</b>. The fault recovery program <b>110</b> executes recovery processing from a fault when the fault occurs in a device disposed in the computer system. The boot redundancy program <b>111</b> makes redundant a network path for connecting the server <b>102</b> to the external disk device <b>103</b> used by the server <b>102</b> for booting (i.e., starting), and executes security setting. The management server <b>101</b> is, for example, a computer equipped with a CPU, a memory, a network card, and the like (refer to <figref idrefs="DRAWINGS">FIG. 33</figref>).
p-0059<figref idrefs="DRAWINGS">FIG. 2</figref> is s block diagram showing a configuration of the server <b>102</b> in detail according to the first embodiment of this invention.
p-0060The server <b>102</b> includes a memory <b>201</b>, a CPU <b>202</b>, a nonvolatile memory <b>203</b>, an adaptor <b>120</b>, a NIC <b>121</b>, and a baseboard management controller (BMC) <b>205</b>.
p-0061The memory <b>201</b> is, for example, a semiconductor memory, for storing a program and data. In the memory <b>201</b> of this embodiment, as a program, a boot program <b>210</b> executed when the server <b>102</b> boots is stored.
p-0062The CPU <b>202</b> is a processor for executing the program stored in the memory <b>201</b>.
p-0063A unique identifier (ID) <b>204</b> is stored in a memory (not shown) disposed in the adaptor <b>120</b>. When the adaptor <b>120</b> is a network adaptor, the ID <b>204</b> is, for example, a MAC address or an IP address. When the adaptor <b>120</b> is a host bus adaptor of a fibre channel, the ID <b>204</b> is, for example, a world wide name (WWN).
p-0064The BMC <b>205</b> mainly monitors or controls hardware of the server <b>102</b>. When a fault occurs in the hardware of the server <b>102</b>, a fault detection function <b>250</b> can detect a fault to notify the fault to the outside of the computer system. Through the BMC <b>205</b>, power can be turned ON or OFF for the sever <b>102</b> from a remote place. The fault detection function <b>250</b> may be a program stored in a memory (not shown) of the BMC <b>205</b> to be executed by a processor (not shown) of the BMC <b>205</b>. Alternatively, the fault detection function <b>250</b> may be realized as a hardware logic.
p-0065The nonvolatile memory <b>203</b> is, for example, a nonvolatile memory such as an EEPROM or a hard disk drive. In the nonvolatile memory <b>203</b>, a device used by the server <b>102</b> for booting is preregistered.
p-0066The boot program <b>210</b> is, for example, a program such as a system BIOS or an sEFI. This program is operated to boot the server <b>102</b> by using the device registered in the nonvolatile memory <b>203</b> when power is turned ON for the server <b>102</b>. To be specific, the boot program <b>210</b> executes booting by reading the OS or the like from the disk <b>131</b> registered in the nonvolatile memory <b>203</b> via an access path registered in the nonvolatile memory <b>203</b>. Further, the boot program <b>210</b> can execute network booting. The network booting means that the adaptor <b>120</b> receives a program from the network to execute booting. The network booting is, for example, executed based on a PXE protocol or the like.
p-0067<figref idrefs="DRAWINGS">FIG. 33</figref> is a block diagram showing a configuration of the management server <b>101</b> in detail according to the first embodiment of this invention.
p-0068The management server <b>101</b> includes a memory <b>3301</b>, a CPU <b>3302</b>, and a NIC <b>3303</b>.
p-0069The memory <b>3301</b> is, for example, a semiconductor memory, for storing a program and data. The fault recovery program <b>110</b> and the booth path redundancy program <b>111</b> are programs stored in the memory <b>3301</b>. Those programs are executed by the CPU <b>3302</b>.
p-0070The CPU <b>3302</b> is a processor for executing the program stored in the memory <b>3301</b>. To be specific, the CPU <b>3302</b> executes the fault recovery program <b>110</b> and the boot path redundancy program <b>111</b>. Accordingly, in description to be made below, processing executed by those programs is actually executed by the CPU <b>3302</b>.
p-0071The NIC <b>3303</b> is an interface connected to the management NW-SW <b>105</b>.
p-0072<figref idrefs="DRAWINGS">FIG. 3</figref> is an explanatory diagram showing the fault recovery program <b>110</b> and the boot path redundancy program <b>111</b> in detail according to the first embodiment of this invention.
p-0073The fault recovery program <b>110</b> includes a fault monitoring module <b>301</b>, an application stop server retrieval module <b>302</b>, an application resuming server retrieval module <b>303</b>, a boot setting changing module <b>304</b>, a server power control module <b>305</b>, a server information table <b>306</b>, and an external disk device information table <b>307</b>.
p-0074The fault monitoring module <b>301</b> monitors a state of a device such as the server <b>102</b>, the network switch <b>104</b>, the external disk device <b>103</b>, or the controller <b>130</b> of the computer system to detect a fault occurrence in the device.
p-0075The application stop server retrieval module <b>302</b> retrieves the server <b>102</b> disabled to operate due to the fault in the device of the computer system.
p-0076When one of the servers <b>102</b> is disabled to operate, the application resuming server retrieval module <b>303</b> retrieves another server <b>102</b> which resumes the application of the server <b>102</b> which is disabled to operate and path information of a network used by the another server <b>102</b>.
p-0077The boot setting changing module <b>304</b> changes boot setting of the server <b>102</b>. The boot setting changing module <b>304</b> includes, for example, a DHCP server function of booting the server <b>102</b> by using the PXE protocol, and can transmit a boot setting changing program <b>340</b> to the server <b>102</b>.
p-0078The boot setting changing program <b>340</b> is executed by the server <b>102</b> which has received the boot setting changing program <b>340</b> to change setting of the boot program <b>210</b> of the server <b>102</b>. To be specific, by changing information registered in the nonvolatile memory <b>203</b>, the boot setting changing program <b>340</b> can change the disk <b>131</b> used by the boot program <b>210</b> for executing booting, and an access path used for accessing the disk <b>131</b>. The access path passes specifically the NW-SW <b>104</b> or the controller <b>130</b> used for accessing.
p-0079The server power control module <b>305</b> executes power control for power-ON or OFF or resetting for the server <b>102</b>.
p-0080The server information table <b>306</b> manages a state of the server <b>102</b>, information of the external disk device <b>103</b> used by the server <b>102</b>, or information of a network path used by the server <b>102</b>.
p-0081The external disk device information table <b>307</b> manages information such as a port ID of the external disk device <b>103</b>. The port ID is an identifier (e.g., WWN) added to a port disposed in the controller <b>130</b> of the external disk device <b>103</b>.
p-0082The boot path redundancy program <b>111</b> includes a logical disk control module <b>320</b>, a synchronous disk control module <b>321</b>, a network security control module <b>322</b>, and a redundant path information table <b>323</b>.
p-0083The logical disk control module <b>320</b> controls a logical disk constituted of the disk <b>131</b> in the external disk device <b>103</b>. The logical disk is a virtual storage volume recognized as one information storage device by the server <b>102</b>.
p-0084The synchronous disk control module <b>321</b> controls a synchronous disk. The synchronous disk is a disk <b>131</b> which records contents identical to those of a certain disk <b>131</b>, and is included in the external disk device <b>103</b> different from that in which the certain disk <b>131</b> is included. Data recorded in the certain disk <b>131</b> to be used by the server <b>102</b> is also recorded in a synchronous disk of the disk <b>131</b>.
p-0085The network security control module <b>322</b> controls security setting in the network.
p-0086The redundant path information table <b>323</b> manages network path which enables access to the disk <b>131</b> of the computer system.
p-0087<figref idrefs="DRAWINGS">FIG. 4</figref> is an explanatory diagram showing the server information table <b>306</b> according to the first embodiment of this invention.
p-0088Columns <b>401</b> to <b>408</b> of the server management table <b>306</b> include a list of servers <b>102</b> in the computer system, an application state of each server <b>102</b>, a disk in the network used by each server <b>102</b>, and information regarding a used network path.
p-0089In the column <b>401</b>, information for identifying the server <b>102</b> in the computer system is registered. For example, the column <b>401</b> may be a serial number, a UUID, a MAC address, or the like of the server <b>102</b>. In an example of <figref idrefs="DRAWINGS">FIG. 2</figref>, “S<b>1</b>”, “S<b>2</b>”, or the like is registered in the column <b>401</b>.
p-0090The column <b>402</b> indicates a state of the server <b>102</b> registered in the column <b>401</b>. For example, when the server <b>102</b> is being operated, the column <b>402</b> corresponding to the server <b>102</b> is “being operated”. The column <b>402</b> corresponding to the server <b>102</b> not being operated is “standing-by”.
p-0091When another server <b>102</b> takes over the application of the server <b>102</b> being operated, the column <b>402</b> corresponding to the latter server <b>102</b> is “stopped”. In the column <b>402</b> corresponding to the latter server <b>102</b>, an identifier of the server <b>102</b> which has taken over the application is registered. For example, as shown in <figref idrefs="DRAWINGS">FIG. 4</figref>, when an application of the server “S<b>2</b>” is taken over by the server “S<b>7</b>”, “change to S<b>7</b>” is registered in the column <b>402</b> corresponding to “S<b>2</b>”.
p-0092On the other hand, in the column <b>402</b> of the server <b>102</b> which has taken over the application, “being operated” and an identifier of the server <b>102</b> being operated is registered. In the case of the server “S<b>7</b>” of <figref idrefs="DRAWINGS">FIG. 2</figref>, “change from S<b>2</b>” is registered in the column <b>402</b>.
p-0093In the column <b>403</b>, an identifier of a disk image indicating contents of the disk <b>131</b> used by the server <b>102</b> registered in the column <b>401</b> is registered. The disk image identifier is unique in the computer system. For example, when a plurality of disks <b>131</b> record identical disk images, the disks <b>131</b> are indicated by identical disk image identifiers. The disk image identifier corresponds to a column <b>601</b> of the redundant path information table <b>323</b> of the booth path redundancy program <b>111</b> described below.
p-0094In the column <b>404</b>, registered is information indicating which of the network paths specified by the columns <b>405</b> to <b>408</b> is used by the server <b>102</b> registered in the column <b>401</b>. To be specific, “YES” is registered in the column <b>404</b> corresponding to a path used by the server <b>102</b>.
p-0095When there are a plurality of network paths used by one server <b>102</b> for accessing one disk <b>131</b>, a path being used is registered for each network path. In the example of <figref idrefs="DRAWINGS">FIG. 4</figref>, the server “S<b>0</b>” can use two network paths for accessing the disk image “D<b>0</b>”. Accordingly, the column <b>404</b> corresponding to the server “S<b>0</b>” and the disk “D<b>0</b>” is divided into two, and “YES” and “NO” are respectively registered.
p-0096The server “S<b>0</b>” is a server <b>102</b> identified by the server identifier “S<b>0</b>”. The disk image “D<b>0</b>” is a disk image identified by the disk image identifier “D<b>0</b>”. A similar notation method will be applied to portions of the computer system of this embodiment hereinafter.
p-0097The columns <b>405</b> to <b>408</b> indicate pieces of information regarding the network path used by the server <b>102</b> for accessing the disk <b>131</b>.
p-0098The column <b>405</b> indicates an identifier (WWN) of the adaptor <b>120</b> disposed in the server <b>102</b> registered in the column <b>401</b>.
p-0099The column <b>406</b> indicates an identifier of the NW-SW <b>104</b> connected to the adaptor <b>120</b> registered in the column <b>405</b>.
p-0100The column <b>407</b> indicates an identifier of the external disk device <b>103</b> connected to the NW-SW <b>104</b> registered in the column <b>406</b>.
p-0101The column <b>408</b> indicates an identifier of a controller <b>130</b> connected to the NW-SW <b>104</b> indicated by the column <b>406</b> among the controllers <b>130</b> disposed in the external disk device <b>103</b> registered in the column <b>407</b>.
p-0102For example, in an example of <figref idrefs="DRAWINGS">FIG. 4</figref>, corresponding to a value “S<b>0</b>” of the column <b>401</b>, a value “being operated” of the column <b>402</b>, a value “D<b>0</b>” of the column <b>403</b>, values “YES” and “NO” of the column <b>404</b>, a value “WWN<b>0</b>” of the column <b>405</b>, a value “SW<b>0</b>” of the column <b>406</b>, values “ARRAY<b>0</b>” and “ARRAY<b>1</b>” of the column <b>407</b>, and values “CTRL<b>0</b>” and “CTRL<b>0</b>” of the column <b>408</b> are registered. Those values indicate the following state.
p-0103That is, the server <b>121</b> whose identifier is “S<b>0</b>” includes an adaptor <b>120</b> whose identifier is “WWN<b>0</b>”. The adaptor <b>120</b> whose identifier is “WWN<b>0</b>” is connected to a controller <b>130</b> whose identifier is “CTRL<b>0</b>” of the external disk device <b>103</b> whose identifier is “ARRAY<b>0</b>” via the NW-SW <b>104</b> whose identifier is “SW<b>0</b>”. The adaptor <b>120</b> whose identifier is “WWN<b>0</b>” is also connected to a controller <b>130</b> whose identifier is “CTRL<b>0</b>” of the external disk device <b>103</b> whose identifier is “ARRAY<b>1</b>” via the NW-SW<b>104</b> whose identifier is “SW<b>0</b>”. The external disk devices “ARRAY<b>0</b>” and “ARRAY<b>1</b>” both include disks <b>131</b> in which disk images “D<b>0</b>” have been recorded.
p-0104In this example, the server “S<b>0</b>” is operated by accessing the disk “D<b>0</b>” by using a path reaching the external disk device “ARRAY<b>0</b>” via the adaptor “WWN<b>0</b>”, the NW-SW “SW<b>0</b>” and the controller “CTRL<b>0</b>”. Alternatively, the server “S<b>0</b>” can access the disk “D<b>0</b>” by using a path reaching the external disk device “ARRAY<b>1</b>” via the adaptor “WWN<b>0</b>”, the NW-SW “SW<b>0</b>”, and the controller “CTRL<b>0</b>”. However, in the example of <figref idrefs="DRAWINGS">FIG. 4</figref>, this path is not used.
p-0105<figref idrefs="DRAWINGS">FIG. 5</figref> is an explanatory diagram showing the external disk device information table <b>307</b> according to the first embodiment of this invention.
p-0106The external disk device information table <b>307</b> manages information of the external disk device <b>103</b> disposed in the computer system.
p-0107A column <b>501</b> indicates an identifier of the external disk device <b>103</b> present in the computer system. As shown in <figref idrefs="DRAWINGS">FIG. 1</figref>, the computer system of this embodiment includes two external disk devices <b>103</b>. Thus, in the column <b>501</b>, identifiers “ARRAY<b>0</b>” and “ARRAY<b>1</b>” of the two external devices <b>103</b> are registered. The column <b>501</b> corresponds to the column <b>407</b> shown in <figref idrefs="DRAWINGS">FIG. 4</figref>.
p-0108A column <b>502</b> is an identifier of the controller <b>130</b> disposed in the external disk device <b>103</b> indicated by the column <b>501</b>. As shown in <figref idrefs="DRAWINGS">FIG. 1</figref>, the external disk device <b>103</b> of this embodiment includes two controllers <b>130</b>. Accordingly, in the column <b>502</b>, identifiers “CTRL<b>0</b>” and “CTRL<b>1</b>” of the two controllers <b>130</b> are registered for each external disk device <b>103</b>. The column <b>502</b> corresponds to the column <b>408</b> shown in <figref idrefs="DRAWINGS">FIG. 4</figref>.
p-0109A column <b>503</b> indicates an identifier (i.e., port ID) of a port (not shown) disposed in the controller <b>130</b> indicated by the column <b>502</b>. For example, when the port of the controller <b>130</b> is connected to the fibre channel network, WWN or the like of the port may be registered in the column <b>503</b>. When the port is connected to the network using iSCSI or TCP of Ethernet protocol such as a network file system, an IP address, a MAC address, or the like of the port may be registered in the column <b>503</b>.
p-0110In the example of <figref idrefs="DRAWINGS">FIG. 5</figref>, a world wide port name (WWPN) is used as a port ID. To be specific, port ID's of ports disposed in the controllers “CTRL<b>0</b>” and “CTRL<b>1</b>” of the external disk device “ARRAY<b>0</b>” are respectively “WWPN<b>0</b>” and “WWPN<b>1</b>”. Port ID'S of ports disposed in the controllers “CTRL<b>0</b>” and “CTRL<b>1</b>” of the controllers of the external disk device “ARRAY<b>1</b>” are respectively “WWPN<b>2</b>” and “WWPN<b>3</b>”.
p-0111<figref idrefs="DRAWINGS">FIG. 6</figref> is an explanatory diagram showing the redundant path information table <b>323</b> according to the first embodiment of this invention.
p-0112The redundant path information table <b>323</b> manages information of a disk image present in the computer system.
p-0113A column <b>601</b> indicates an identifier of a disk image. As there are five disk images in the computer system of this embodiment, in the column <b>601</b>, identifiers “D<b>0</b>”, “D<b>1</b>”, “D<b>2</b>”, “D<b>4</b>”, and “D<b>5</b>” of the five disk images are registered. The column <b>601</b> corresponds to the column <b>403</b> shown in <figref idrefs="DRAWINGS">FIG. 4</figref>.
p-0114A column <b>602</b> indicates an external disk device <b>103</b> equipped with the disk <b>131</b> in which the disk image indicated by the column <b>601</b> has been recorded. In an example of <figref idrefs="DRAWINGS">FIG. 6</figref>, disk images “D<b>0</b>”, “D<b>1</b>”, and “D<b>2</b>” are recorded in the disk <b>131</b> in the external disk device “ARRAY<b>0</b>”, and disk images “D<b>4</b>” and “D<b>5</b>” are recorded in the disk <b>131</b> in the external disk device “ARRAY<b>1</b>”.
p-0115A column <b>603</b> indicates an identifier for uniquely identifying the disk <b>131</b> included in the external disk device <b>103</b> indicated by the column <b>602</b> to record the disk image indicated by the column <b>601</b>, in the external disk device <b>103</b>. In the example of <figref idrefs="DRAWINGS">FIG. 6</figref>, the disk images “D<b>0</b>”, “D<b>1</b>”, “D<b>2</b>”, “D<b>4</b>”, and “D<b>5</b>” are respectively recorded in disks “VOL<b>0</b>”, “VOL<b>1</b>”, “VOL<b>2</b>”, “VOL<b>4</b>”, and “VOL<b>5</b>”.
p-0116A column <b>604</b> indicates an identifier of a controller <b>130</b> which can access the disk <b>131</b> indicated by the column <b>603</b>. In other words, a device connected to a port included in the controller <b>130</b> indicated by the column <b>604</b> can access the disk <b>131</b> indicated by the column <b>603</b>. The column <b>604</b> may contain information indicating permission of access to the disk <b>131</b> for each port when the controller <b>130</b> includes a plurality of ports.
p-0117In the example of <figref idrefs="DRAWINGS">FIG. 6</figref>, the device connected to the controllers “CTRL<b>0</b>” and “CTRL<b>1</b>” of the external disk device “ARRAY<b>0</b>” can access the disks “VOL<b>0</b>”, “VOL<b>1</b>”, and “VOL<b>2</b>”. Further, the device connected to the controllers “CTRL<b>0</b>” and “CTRL<b>1</b>” of the external disk device “ARRAY<b>1</b>” can access the disks “VOL<b>4</b>” and “VOL<b>5</b>”.
p-0118A column <b>605</b> indicates an identifier of a logical disk which the controller <b>130</b> indicated by the column <b>604</b> gives to the disk <b>131</b>. The logical disk is a logical (virtual in other words) disk set by the controller <b>130</b> to enable the server <b>102</b> to access the disk <b>131</b>. The server <b>102</b> recognizes the logical disk to issue an access request to the logical disk. Upon reception of the access request, the controller <b>130</b> executes access to the disk <b>131</b> corresponding to the logical disk of a request target. Management of the logical disk by the controller <b>130</b> will be described below in detail (refer to <figref idrefs="DRAWINGS">FIG. 7</figref>).
p-0119Each controller <b>130</b> can provide a unique logical disk identifier in the controller <b>130</b> to the disk <b>131</b> used by the controller <b>130</b>. Accordingly, in general, the plurality of controllers <b>130</b> may provide different logical disk identifiers to the same disk <b>131</b>. According to this invention, however, as shown in <figref idrefs="DRAWINGS">FIG. 6</figref>, the controllers <b>130</b> provide the same logical disk identifier to the same disk <b>131</b>.
p-0120In the example of <figref idrefs="DRAWINGS">FIG. 6</figref>, corresponding to the disks “VOL<b>0</b>”, “VOL<b>1</b>”, “VOL<b>2</b>”, “VOL<b>4</b>”, and “VOL<b>5</b>”, logical disk identifiers “LUN<b>0</b>”, “LUN<b>1</b>”, “LUN<b>2</b>”, “LUN<b>4</b>”, and “LUN<b>5</b>” are provided. Accordingly, those logical disk identifiers are registered in the column <b>605</b>.
p-0121A column <b>606</b> indicates an identifier of the external disk device <b>103</b> which includes a synchronous disk of the disk <b>131</b> indicated by the column <b>603</b>. In the example of <figref idrefs="DRAWINGS">FIG. 6</figref>, synchronous disks of the disks “VOL<b>0</b>”, “VOL<b>1</b>”, “VOL<b>2</b>”, “VOL<b>4</b>”, and “VOL<b>5</b>” are included in the external disk device “ARRAY<b>1</b>”. Synchronous disks of the disks “VOL<b>4</b>”, and “VOL<b>5</b>” are included in the external disk device “ARRAY<b>0</b>”.
p-0122A column <b>607</b> indicates an identifier of the disk <b>131</b> which is included in the external disk device <b>103</b> indicated by the column <b>606</b> and which is a synchronous disk of the disk <b>131</b> indicated by the column <b>603</b>. In the example of <figref idrefs="DRAWINGS">FIG. 6</figref>, the synchronous disks of the disks “VOL<b>0</b>”, “VOL<b>1</b>”, “VOL<b>2</b>”, “VOL<b>4</b>”, and “VOL<b>5</b>” are respectively disks “SVOL<b>0</b>”, “SVOL<b>1</b>”, “SVOL<b>2</b>”, “SVOL<b>4</b>” and “SVOL<b>5</b>”.
p-0123A column <b>608</b> indicates an identifier of the controller <b>130</b> which can access the disk <b>131</b> indicated by the column <b>607</b>. The column <b>608</b> may contain information indicating permission of access to the disk <b>131</b> for each port when the controller <b>130</b> includes a plurality of ports.
p-0124In the example of <figref idrefs="DRAWINGS">FIG. 6</figref>, the device connected to the controllers “CTRL<b>0</b>” and “CTRL<b>1</b>” of the external disk device “ARRAY<b>1</b>” can access the disks “SVOL<b>0</b>”, “SVOL<b>1</b>”, and “SVOL<b>2</b>”. The device connected to the controller “CTRL<b>0</b>” of the external disk device “ARRAY<b>0</b>” can access the disk “SVOL<b>4</b>”. Further, the device connected to the controllers “CTRL<b>0</b>” and “CTRL<b>1</b>” of the external disk device “ARRAY<b>0</b>” can access the disk “SVOL<b>5</b>”.
p-0125A column <b>609</b> indicates a logical disk identifier used by the controller <b>130</b> indicated by the column <b>608</b> for identifying the disk <b>131</b> indicated by the column <b>607</b>. In the example of <figref idrefs="DRAWINGS">FIG. 6</figref>, corresponding to the disks “SVOL<b>0</b>”, “SVOL<b>1</b>”, “SVOL<b>2</b>”, “SVOL<b>4</b>”, and “SVOL<b>5</b>”, logical disk identifiers “LUN<b>10</b>”, “LUN<b>11</b>”, “LUN<b>12</b>”, “LUN<b>14</b>”, and “LUN<b>15</b>” are provided.
p-0126<figref idrefs="DRAWINGS">FIG. 7</figref> is an explanatory diagram showing a logical disk management program disposed in the external disk device <b>130</b> according to the first embodiment of this invention.
p-0127For example, the external disk device <b>103</b> of <figref idrefs="DRAWINGS">FIG. 7</figref> corresponds to the external disk device “ARRAY<b>0</b>” of <figref idrefs="DRAWINGS">FIG. 6</figref>.
p-0128Controllers <b>730</b> and <b>731</b> of <figref idrefs="DRAWINGS">FIG. 7</figref> respectively correspond to the controllers <b>130</b> of <figref idrefs="DRAWINGS">FIG. 1</figref>. For example, the controllers <b>730</b> and <b>731</b> respectively correspond to the controllers “CTRL<b>0</b>” and “CTRL<b>1</b>” of <figref idrefs="DRAWINGS">FIG. 6</figref>.
p-0129Logical disk management programs <b>740</b> and <b>741</b> are respectively stored in memories (not shown) of the controllers <b>730</b> and <b>731</b>, and executed by processors (not shown) of the controllers.
p-0130Servers <b>701</b> and <b>702</b> respectively correspond to the servers <b>102</b> of <figref idrefs="DRAWINGS">FIG. 1</figref>.
p-0131NW-SW's <b>703</b> and <b>704</b> respectively correspond to the NW-SW's <b>104</b> of <figref idrefs="DRAWINGS">FIG. 1</figref>.
p-0132Disks <b>733</b>, <b>734</b>, and <b>735</b> respectively correspond to the disks <b>131</b> of <figref idrefs="DRAWINGS">FIG. 1</figref>. For example, the disks <b>733</b>, <b>734</b>, and <b>735</b> respectively correspond to the disks “VOL<b>0</b>”, “VOL<b>1</b>”, and “VOL<b>2</b>” of <figref idrefs="DRAWINGS">FIG. 6</figref>.
p-0133The logical disk management programs <b>740</b> and <b>741</b> generates, for example, logical disks <b>750</b> and <b>751</b> corresponding to a single disk <b>733</b> among the disks <b>733</b>, <b>734</b>, and <b>735</b> present in the external disk device <b>103</b>. The logical disks <b>750</b> and <b>751</b> correspond to the entire disk <b>733</b>. When the external disk device <b>103</b> of <figref idrefs="DRAWINGS">FIG. 7</figref> correspond to the external disk device “ARRAY<b>0</b>” of <figref idrefs="DRAWINGS">FIG. 6</figref>, the logical disks <b>750</b> and <b>751</b> both correspond to the logical disk “LUN<b>0</b>”.
p-0134As a result, the server <b>701</b> connected to a port of the controller <b>731</b> via the NW-SW <b>703</b>, and the server <b>702</b> connected to a port of the controller <b>732</b> via the NW-SW <b>704</b> can both access the disk <b>733</b>.
p-0135Logical disk tables <b>770</b> and <b>771</b> are tables for storing information indicating correspondence between the disks <b>733</b>, <b>734</b>, and <b>735</b> and the logical disks <b>750</b> and <b>751</b> (refer to <figref idrefs="DRAWINGS">FIG. 8</figref>). The logical disk tables <b>770</b> and <b>771</b> are stored in memories (not shown) of the controllers <b>730</b> and <b>731</b>.
p-0136The logical disk management program <b>740</b> and <b>741</b> can generate, delete, or change logical disks <b>750</b> and <b>751</b> under control of the management server <b>101</b> connected to management ports (not shown) of the controllers <b>730</b> and <b>731</b>. When the controllers <b>730</b> and <b>731</b> do not have logical disks <b>740</b> and <b>741</b>, the servers <b>701</b> and <b>702</b> can directly access the disks <b>733</b>, <b>734</b>, and <b>735</b>.
p-0137In <figref idrefs="DRAWINGS">FIG. 7</figref>, the logical disk “LUN<b>0</b>” corresponding to the disk “VOL<b>0</b>” alone is shown. In reality, however, logical disks “LUN<b>1</b>” and “LUN<b>2</b>” corresponding to the disks “VOL<b>1</b>” and “VOL<b>2</b>” may be generated by both of the controllers <b>730</b> and <b>731</b>.
p-0138When the external disk device <b>103</b> shown in <figref idrefs="DRAWINGS">FIG. 7</figref> is the external disk device “ARRAY<b>0</b>” of <figref idrefs="DRAWINGS">FIG. 6</figref>, this external disk device <b>103</b> further includes disks “VOL<b>4</b>” and “VOL<b>5</b>”. In this case, logical disks “LUN<b>4</b>” and “LUN<b>5</b>” corresponding to the disks “SVOL<b>4</b>” and “SVOL<b>5</b>” are generated by both of the controllers <b>730</b> and <b>731</b>.
p-0139<figref idrefs="DRAWINGS">FIG. 8</figref> is an explanatory diagram showing a logical disk table according to the first embodiment of this invention.
p-0140<figref idrefs="DRAWINGS">FIG. 8</figref> shows a representative of the logical disk tables <b>770</b> and <b>771</b> of <figref idrefs="DRAWINGS">FIG. 7</figref> in detail.
p-0141A column <b>801</b> is an identifier of a disk. For example, when identifiers of the disks <b>733</b>, <b>734</b>, and <b>735</b> shown in <figref idrefs="DRAWINGS">FIG. 7</figref> are respectively “VOL<b>0</b>”, “VOL<b>1</b>”, and “VOL<b>2</b>”, those identifiers are registered in the column <b>801</b>. When the external disk device <b>103</b> of <figref idrefs="DRAWINGS">FIG. 7</figref> is the external disk device “ARRAY<b>0</b>” of <figref idrefs="DRAWINGS">FIG. 6</figref>, in the column <b>801</b>, “SVOL<b>4</b>” and “SVOL<b>5</b>” are further registered. Accordingly, the column <b>801</b> corresponds to the columns <b>603</b> and <b>608</b> of <figref idrefs="DRAWINGS">FIG. 6</figref>.
p-0142A column <b>802</b> is an identifier of a logical disk corresponding to the disk indicated by the column <b>801</b>. In an example of <figref idrefs="DRAWINGS">FIG. 8</figref>, as logical disk identifiers corresponding to the disks “VOL<b>0</b>”, “VOL<b>1</b>”, “VOL<b>2</b>”, “SVOL<b>4</b>”, and “SVOL<b>5</b>”, “LUN<b>0</b>”, “LUN<b>1</b>”, “LUN<b>2</b>”, “LUN<b>14</b>”, and “LUN<b>15</b>” are respectively registered. The column <b>802</b> corresponds to the columns <b>605</b> and <b>609</b> of <figref idrefs="DRAWINGS">FIG. 6</figref>.
p-0143<figref idrefs="DRAWINGS">FIG. 9</figref> is an explanatory diagram showing a disk synchronization program disposed in the external disk device according to the first embodiment of this invention.
p-0144In an example of <figref idrefs="DRAWINGS">FIG. 9</figref>, external disk devices <b>930</b> and <b>931</b> correspond to the external disk devices “ARRAY<b>0</b>” and “ARRAY<b>1</b>”. A controller <b>940</b> corresponds to one of the controllers “CTRL<b>0</b>” and “CTRL<b>1</b>” of the external disk device “ARRAY<b>0</b>”. A controller <b>941</b> corresponds to one of the controllers “CTRL<b>0</b>” and “CTRL<b>1</b>” of the external disk device “ARRAY<b>1</b>”. The controllers <b>940</b> and <b>941</b> are connected via a network <b>903</b>. Disks <b>970</b> and <b>971</b> respectively correspond to the disks “VOL<b>0</b>” and “SVOL<b>0</b>”.
p-0145Disk synchronization programs <b>950</b> and <b>951</b> are respectively stored in memories (not shown) of the controllers <b>940</b> and <b>941</b>, and executed by processors (not shown) of the controllers.
p-0146Each of the disk synchronization programs <b>950</b> and <b>951</b> generates a synchronous disk <b>971</b> for recording contents similar to those of the disk image “D<b>0</b>” recorded in the disk <b>970</b> of the external disk device <b>930</b>, in the external disk device <b>931</b>. In the example of <figref idrefs="DRAWINGS">FIG. 9</figref>, the external disk device <b>930</b> includes a disk “VOL<b>0</b>”. In the external disk device <b>931</b>, a disk “SVOL<b>0</b>” which is a synchronous disk of the disk “VOL<b>0</b>” is generated. In the disks “VOL<b>0</b>” and “SVOL<b>0</b>”, identical disk images “D<b>0</b>” are recorded.
p-0147For convenience of explanation, <figref idrefs="DRAWINGS">FIG. 9</figref> shows the disks “VOL<b>0</b>” and “SVOL<b>0</b>” alone. In reality, however, each external disk device may include other disks (e.g., “VOL<b>1</b>”, “SVOL<b>1</b>”, and the like).
p-0148A server <b>901</b> is connected to a port <b>980</b> disposed in the controller <b>940</b> via an NW-SW <b>902</b>, and to a port <b>981</b> disposed in the controller <b>941</b>. In this case, the controllers <b>940</b> and <b>941</b> can both access the same disk image “D<b>0</b>”.
p-0149Synchronous disk tables <b>960</b> and <b>961</b> are tables for storing information indicating correspondence between a disk <b>970</b> and a synchronous disk <b>971</b> (refer to <figref idrefs="DRAWINGS">FIG. 10</figref>). The synchronous disk tables <b>960</b> and <b>961</b> are stored in memories (not shown) of the controllers <b>940</b> and <b>941</b>.
p-0150The disk synchronization programs <b>950</b> and <b>951</b> can generate, delete or change the synchronous disk <b>971</b> under control of the management server <b>101</b> connected to management ports (not shown) of the controllers <b>930</b> and <b>931</b>.
p-0151<figref idrefs="DRAWINGS">FIG. 10</figref> is an explanatory diagram showing a synchronous disk table according to the first embodiment of this invention.
p-0152<figref idrefs="DRAWINGS">FIG. 10</figref> shows the synchronous disk table <b>960</b> of <figref idrefs="DRAWINGS">FIG. 9</figref> in detail as an example.
p-0153A column <b>1001</b> indicates an identifier of a disk. The column <b>1001</b> corresponds to the column <b>603</b> of <figref idrefs="DRAWINGS">FIG. 6</figref>.
p-0154A column <b>1002</b> indicates an identifier of the external disk device <b>103</b> in which the synchronous disk of the disk <b>131</b> indicated by the column <b>1001</b> is present. The column <b>1002</b> corresponds to the column <b>606</b> of <figref idrefs="DRAWINGS">FIG. 6</figref>.
p-0155A column <b>1003</b> indicates an identifier of a synchronous disk. The column <b>1003</b> corresponds to the column <b>607</b> of <figref idrefs="DRAWINGS">FIG. 6</figref>.
p-0156For example, when the external disk device <b>930</b> of <figref idrefs="DRAWINGS">FIG. 9</figref> corresponds to the external disk device “ARRAY<b>0</b>” of <figref idrefs="DRAWINGS">FIG. 6</figref>, “VOL<b>0</b>”, “VOL<b>1</b>”, and “VOL<b>2</b>” are registered in the column <b>1001</b>. In the column <b>1002</b>, “ARRAY<b>1</b>” is registered corresponding to “VOL<b>0</b>”, “VOL<b>1</b>”, and “VOL<b>2</b>”. In the column <b>1003</b>, “SVOL<b>0</b>”, “SVOL<b>1</b>”, and “SVOL<b>2</b>” are registered corresponding to “VOL<b>0</b>”, “VOL<b>1</b>”, and “VOL<b>2</b>”. This means that synchronous disks of the disks “VOL<b>0</b>”, “VOL<b>1</b>”, and “VOL<b>2</b>” of the external disk device “ARRAY<b>0</b>” are respectively disks “SVOL<b>0</b>”, “SVOL<b>1</b>”, and “SVOL<b>2</b>” in the external disk device “ARRAY<b>1</b>”.
p-0157<figref idrefs="DRAWINGS">FIG. 11</figref> is an explanatory diagram of a security control program provided in the external disk device <b>103</b> according to the first embodiment of this invention.
p-0158The security control program <b>1103</b> is stored in a memory (not shown) of the controller <b>130</b> to be executed by a processor (not shown) of the controller <b>130</b>.
p-0159The security control program <b>1103</b> permits or inhibits access to a logical disk from the server <b>102</b>. As an example, as shown in <figref idrefs="DRAWINGS">FIG. 11</figref>, a case where a port disposed in the controller <b>130</b>, an adaptor <b>1110</b> disposed in a server <b>1101</b> and an adaptor <b>1120</b> disposed in a server <b>1102</b> are interconnected via the NW-SW <b>104</b> will be described. The adaptors <b>1110</b> and <b>1120</b> are respectively identified by ID <b>1111</b> and ID <b>1121</b>.
p-0160In this case, the security control program <b>1103</b> permits access to a logical disk <b>1130</b> from the server <b>1101</b> and access to a logical disk <b>1131</b> from the server <b>1102</b>, while the security control program <b>1103</b> inhibits access to the logical disk <b>1131</b> from the server <b>1101</b> and access to the logical disk <b>1130</b> from the server <b>1102</b>.
p-0161As a result, the server <b>1101</b> can access the logical disk <b>1130</b> but not the logical disk <b>1131</b>. The server <b>1102</b> can access the logical disk <b>1131</b> but not the logical disk <b>1130</b>. Control of the access permission or inhibition is executed by setting access permission mapping between the ID <b>1111</b> and the ID <b>1121</b> and the logical disks <b>1130</b> and <b>1131</b> by the security control program <b>1103</b>.
p-0162The description has been made by way of example in which the disks <b>1130</b> and <b>1131</b> are logical disks. However, the disks <b>1130</b> and <b>1131</b> may be disks <b>131</b> of <figref idrefs="DRAWINGS">FIG. 1</figref>, logical disks, or synchronous disks.
p-0163A disk mapping table <b>1132</b> of <figref idrefs="DRAWINGS">FIG. 11</figref> is a table for storing information indicating a mapping relation between the logical disks <b>1130</b> and <b>1131</b> and the ID <b>1111</b> and the ID <b>1121</b>. The security control program <b>1103</b> can set or release mapping between the logical disks <b>11130</b> and <b>1131</b> and the ID <b>1111</b> and the ID <b>1121</b> under control of the management server <b>101</b> connected to the management port (not shown) of the controller <b>130</b>.
p-0164<figref idrefs="DRAWINGS">FIG. 12</figref> is an explanatory diagram showing the disk mapping table <b>1132</b> according to the first embodiment of this invention.
p-0165<figref idrefs="DRAWINGS">FIG. 12</figref> shows the disk mapping table <b>1132</b> of <figref idrefs="DRAWINGS">FIG. 11</figref> in detail as an example.
p-0166A column <b>1201</b> indicates an identifier of a logical disk. The column <b>1201</b> corresponds to the columns <b>605</b> and <b>609</b> of <figref idrefs="DRAWINGS">FIG. 6</figref>. When the controller <b>130</b> of the external disk device <b>103</b> is not equipped with the logical disk management programs <b>740</b> and <b>741</b> shown in <figref idrefs="DRAWINGS">FIG. 7</figref>, in the column <b>1201</b>, an identifier of the disk <b>131</b> of <figref idrefs="DRAWINGS">FIG. 1</figref> or an identifier of the synchronous disk <b>971</b> of <figref idrefs="DRAWINGS">FIG. 9</figref> may be registered.
p-0167A column <b>1202</b> indicates an ID of an adaptor permitted to access the logical disk indicated by the column <b>1201</b>. For example, in the column <b>1202</b>, the ID <b>1111</b> of the adaptor <b>1110</b> and the ID <b>1121</b> of the adaptor <b>1120</b> of <figref idrefs="DRAWINGS">FIG. 11</figref> are registered.
p-0168In the example of <figref idrefs="DRAWINGS">FIG. 12</figref>, in the column <b>1201</b>, logical disks “LUN<b>0</b>”, “LUN<b>1</b>”, “LUN<b>2</b>”, “LUN<b>4</b>”, “LUN<b>5</b>”, and “LUN<b>12</b>” are registered. Then, corresponding to these logical disks, “WWN<b>0</b>”, “WWN<b>1</b>”, “WWN<b>2</b>”, “WWN<b>4</b>”, “WWN<b>5</b>”, and “WWN<b>7</b>” are registered in the column <b>1202</b>. This indicates that the adaptors “WWN<b>0</b>”, “WWN<b>1</b>”, “WWN<b>2</b>”, “WWN<b>4</b>”, “WWN<b>5</b>”, and “WWN<b>7</b>” of the server <b>102</b> can access the logical disks “LUN<b>0</b>”, “LUN<b>1</b>”, “LUN<b>2</b>”, “LUN<b>4</b>”, “LUN<b>5</b>”, and “LUN<b>12</b>”, respectively. On the other hand, for example, the adaptor “WWN<b>0</b>” cannot access the logical disk “LUN<b>1</b>”.
p-0169<figref idrefs="DRAWINGS">FIG. 13</figref> is an explanatory diagram showing an application sequence executed by each device according to the first embodiment of this invention.
p-0170The shown sequence is an application sequence of an application stop server <b>1301</b>, an application resuming server <b>1302</b>, a fault recovery program <b>1303</b>, and a boot path redundancy program <b>1304</b>. The application stop server <b>1301</b> is a server <b>102</b> inaccessible to the disk <b>131</b> used for pursuing an application due to a fault of the computer system among the servers <b>102</b> shown in <figref idrefs="DRAWINGS">FIG. 1</figref>. As the application stop server <b>1301</b> is inhibited to access the disk <b>131</b>, the application stop server <b>1301</b> cannot continue the application thereof. The application resuming server <b>1302</b> is a server <b>102</b> which takes over the application from the application stop server <b>1301</b> among the servers <b>102</b> shown in <figref idrefs="DRAWINGS">FIG. 1</figref>. The fault recovery program <b>1303</b> and the boot path redundancy program <b>1304</b> are respectively the fault recovery program <b>110</b> and the boot path redundancy program <b>111</b> shown in <figref idrefs="DRAWINGS">FIG. 3</figref>.
p-0171First, the boot path redundancy program <b>1304</b> executes redundancy of a boot path (step <b>1340</b>). As a result of executing the step <b>1340</b>, a disk image used by the application stop server <b>1301</b> is set in a state to be accessed by a certain server <b>102</b> via the ports of one or more controllers <b>130</b> of one or more external disk devices <b>103</b>. The disk image used by the application stop server <b>1301</b> is a disk image used by the application stop server <b>1301</b> for booting, recording or referring to data. At the point of this time, however, due to security setting of the network, the application stop server <b>1301</b> alone is in a state of being permitted to access the disk image used by the application stop server <b>1301</b>. Processing of the step <b>1340</b> will be described below in detail (refer to <figref idrefs="DRAWINGS">FIG. 14</figref>).
p-0172Next, the application stop server <b>1301</b> starts the application thereof (step <b>1310</b>).
p-0173A fault occurs in a certain device of the computer system. At this time, the fault recovery program <b>1303</b> detects the occurrence of the fault in the device (step <b>1330</b>).
p-0174Then, the fault recovery program <b>1303</b> retrieves the server <b>102</b> whose application is stopped due to the fault of the device (step <b>1331</b>). In the example of <figref idrefs="DRAWINGS">FIG. 13</figref>, the server <b>102</b> discovered as a result of this retrieval is the application stop server <b>1301</b>. In the step <b>1331</b>, the plurality of application stop servers <b>1301</b> may be discovered.
p-0175The fault recovery program <b>1303</b> requests power-OFF for the application stop server <b>1301</b> (step <b>1332</b>). The application stop server <b>1301</b> that has received the request turns power OFF (step <b>1311</b>). The application stop server <b>1301</b> may execute shutting-down of the OS, a stopping procedure of an application, or work for fault analysis such as memory dump acquisition or log acquisition before the power-OFF. After the fault recovery program <b>1303</b> confirms the stop of the application stop server <b>1301</b>, the process proceeds to a step <b>1333</b>.
p-0176In the step <b>1333</b>, the fault recovery program <b>1303</b> retrieves the application resuming server <b>1302</b>. To be specific, the server <b>102</b> accessible to the disk image which was used by the application stop server <b>1301</b> and connected to the port of the fault-free controller <b>130</b> without interpolation of the faulted device is retrieved as the application resuming server <b>1302</b>. When a plurality of application stop servers <b>1301</b> are present, the fault recovery program <b>1303</b> retrieves the same number of application resuming servers <b>1302</b>.
p-0177Upon completion of the retrieval of the application resuming server <b>1302</b>, the boot path redundancy program <b>1304</b> changes network security setting (step <b>1341</b>). To be specific, the boot path redundancy program <b>1304</b> changes security setting of the network so that the application resuming server <b>1302</b> can access the disk image used by the application stop server <b>1301</b>.
p-0178Upon completion of security setting change of the network, the fault recovery program <b>1303</b> boots the application resuming server <b>1302</b> through the network to change boot setting of the application resuming server <b>1302</b> (step <b>1334</b>). At this time, the fault recovery program <b>1303</b> transmits the boot setting changing program <b>340</b> to the application resuming server <b>1302</b>. As a result, the application resuming server <b>1302</b> is booted through the network (step <b>1320</b>). Then, the application resuming server <b>1302</b> updates a parameter necessary for booting stored in the application resuming server <b>1302</b> by executing the boot setting changing program <b>340</b> transmitted from the fault recovery program <b>1303</b>.
p-0179Upon completion of boot setting change, the fault recovery program <b>1303</b> instructs the application resuming server <b>1302</b> to use the disk image used by the application stop server <b>1301</b> to boot (step <b>1335</b>).
p-0180The application resuming server <b>1302</b> that has received the instruction of the step <b>1335</b> boots by using the disk image used by the application stop server <b>1301</b> (step <b>1321</b>). To be specific, the application resuming server <b>1302</b> boots by reading the OS or the like from the disk image used by the application stop server <b>1301</b>.
p-0181Then, the application resuming server <b>1302</b> resumes the application executed by the application stop server <b>1301</b> (step <b>1332</b>).
p-0182The sequence shown in <figref idrefs="DRAWINGS">FIG. 13</figref> will be described below in detail.
p-0183<figref idrefs="DRAWINGS">FIG. 14</figref> is a flowchart showing redundancy of the boot path executed by the boot path redundancy program <b>111</b> according to the first embodiment of this invention.
p-0184<figref idrefs="DRAWINGS">FIG. 14</figref> shows the step <b>1340</b> of <figref idrefs="DRAWINGS">FIG. 13</figref> in detail. The sequence of <figref idrefs="DRAWINGS">FIG. 14</figref> is executed by the logical disk control module <b>320</b> and the synchronous disk control module <b>321</b>.
p-0185Processing of <figref idrefs="DRAWINGS">FIG. 14</figref> is executed by targeting the disk <b>131</b> when there is a disk image recorded in only one disk <b>131</b> in the computer system. For example, when the disk image “D<b>0</b>” is recorded in the disk “VOL<b>0</b>” alone, the processing of <figref idrefs="DRAWINGS">FIG. 14</figref> is executed by targeting the disk “VOL<b>0</b>”. As a result, a disk “SVOL<b>0</b>” is created.
p-0186First, the logical disk control module <b>320</b> requests creation of a logical disk corresponding to the disk <b>131</b> to be processed to the logical disk management program of the external disk device by referring to the redundant path information table <b>323</b> (step <b>1401</b>). For example, the logical disk control module <b>320</b> refers to the redundant path information table <b>323</b> of <figref idrefs="DRAWINGS">FIG. 6</figref> to request creation of the logical disk indicated by the column <b>605</b> in the controller indicated by the column <b>604</b> as a logical disk corresponding to the disk <b>131</b> indicated by the column <b>603</b> to the external disk device <b>103</b> indicated by the column <b>602</b>.
p-0187The external disk device <b>103</b> that has received the request creates a logical disk in response to the request. Upon completion of logical disk creation, the external disk device <b>103</b> transmits a completion notification to the logical disk control module <b>320</b>.
p-0188The logical disk control module <b>320</b> receives the logical disk creation completion notification from the logical disk management program of the external disk device <b>103</b> (step <b>1402</b>).
p-0189Subsequently, the synchronous disk control module <b>321</b> refers to the redundant path information table <b>323</b> to request creation of a synchronous disk to the synchronous external disk device (step <b>1403</b>). For example, the synchronous disk control module <b>321</b> refers to the redundant path information table <b>323</b> of <figref idrefs="DRAWINGS">FIG. 6</figref> to request creation of the synchronous disk indicated by the column <b>607</b> to the synchronous external disk device indicated by the column <b>606</b>.
p-0190The external disk device <b>103</b> that has received the request creates a synchronous disk in response to the request. Then, the external disk device <b>103</b> transmits a completion notification to the synchronous disk control module <b>321</b>.
p-0191The synchronous disk control module <b>321</b> receives a completion notification of synchronous disk creation and synchronization start from the synchronous external device (step <b>1404</b>).
p-0192Then, the logical disk control module <b>320</b> refers to the redundant path information table <b>323</b> to request creation of a logical disk corresponding to the synchronous disk to the logical disk management program of the synchronous external disk device (step <b>1405</b>). For example, the logical disk control module <b>320</b> requests the external disk device <b>103</b> indicated by the column <b>606</b> of <figref idrefs="DRAWINGS">FIG. 6</figref> to create the logical disk indicated by the column <b>609</b> in the controller indicated by the column <b>608</b> as a logical disk corresponding to the disk <b>131</b> indicated by the column <b>607</b>.
p-0193The external disk device <b>103</b> that has received the request creates a logical disk in response to the request. Upon completion of the logical disk creation, the external disk device <b>103</b> transmits a completion notification to the logical disk control module <b>320</b>.
p-0194The logical disk control module <b>320</b> receives the logical disk creation completion notification from the logical disk management program of the synchronous external disk device (<b>1406</b>).
p-0195Subsequently, the synchronous disk control module <b>321</b> requests the disk synchronization program to start processing of synchronizing contents between the disk <b>131</b> to be processed and the synchronous disk in the synchronous external disk device (step <b>1407</b>). The processing of synchronizing the contents of the disks <b>131</b> means processing of copying contents recorded in one disk <b>131</b> to another disk <b>131</b>. For example, the synchronous disk control module <b>321</b> refers to the redundant path information table <b>323</b> of <figref idrefs="DRAWINGS">FIG. 6</figref> to request the external disk device <b>103</b> indicated by the column <b>602</b> and the external disk device <b>103</b> indicated by the column <b>606</b> to start processing of copying contents recorded in the disk <b>131</b> indicated by the column <b>603</b> to the disk <b>131</b> indicated by the column <b>607</b>. The external disk device <b>103</b> that has received the request starts synchronization of the disks in response to the request. Then, the external disk device <b>103</b> transmits a synchronization start completion notification to the synchronous disk control module <b>321</b>.
p-0196The synchronous disk control module <b>321</b> receives the synchronization start completion notification from the disk synchronization program of the external disk device <b>103</b> (step <b>1408</b>).
p-0197<figref idrefs="DRAWINGS">FIG. 15</figref> is a flowchart showing fault monitoring processing executed by the fault recovery program <b>110</b> according to the first embodiment of this invention.
p-0198The processing shown in <figref idrefs="DRAWINGS">FIG. 15</figref> is executed by the fault monitoring module <b>301</b> in the step <b>1330</b> of <figref idrefs="DRAWINGS">FIG. 13</figref>.
p-0199When a fault occurs in a device constituting the computer system, the fault monitoring module <b>301</b> detects a fault occurrence notification of the device (step <b>1501</b>). For example, the device constituting the computer system is the server <b>102</b>, the adaptor <b>120</b>, the NW-SW <b>104</b>, the external disk device <b>103</b>, or the controller <b>130</b>.
p-0200The fault monitoring module <b>301</b> can communicate with the device constituting the computer system via the network. Each device can notify the fault of the device to the fault monitoring module <b>301</b> by a protocol such as simple network management protocol (SNMP) or proprietary communication means. The fault monitoring module <b>301</b> can detect the occurrence of the fault by receiving the fault occurrence notification from the device. Alternatively, the fault monitoring module <b>301</b> can detect the fault occurrence of the device by periodically making an inquiry about a device state to the device to monitor a state change.
p-0201Then, the fault monitoring module <b>301</b> specifies the device where the fault has occurred (step <b>1502</b>). When the degree of the device fault is low, and the fault has no influence on an application of the computer system, the fault occurrence can be ignored.
p-0202The fault monitoring module <b>301</b> notifies an identifier of the device where the fault has occurred (hereinafter referred to as “faulted device”) to the application stop server retrieval module <b>302</b> and the application resuming server retrieval module <b>303</b> (step <b>1503</b>).
p-0203<figref idrefs="DRAWINGS">FIG. 16</figref> is a flowchart showing application stop server retrieval and server power control executed by the fault recovery program <b>110</b> according to the first embodiment of this invention.
p-0204Processing shown in <figref idrefs="DRAWINGS">FIG. 16</figref> is executed by the application stop server retrieval module <b>302</b> and the server power control module <b>305</b> in the steps <b>1331</b> and <b>1332</b> of <figref idrefs="DRAWINGS">FIG. 13</figref>.
p-0205First, the application stop server retrieval module <b>302</b> receives the identifier of the faulted device from the fault monitoring module <b>301</b> (step <b>1601</b>). This information has been transmitted in the step <b>1503</b> of <figref idrefs="DRAWINGS">FIG. 15</figref>.
p-0206Then, the application stop server retrieval module <b>302</b> refers to the server information table <b>306</b> to retrieve an application stop server <b>1301</b> (step <b>1602</b>). The application stop server <b>1301</b> is a server <b>102</b> which uses the faulted device.
p-0207As an example, a case where a fault occurs in the controller “CTRL<b>1</b>” of the external disk device “ARRAY<b>1</b>” will be described. In this case, in <figref idrefs="DRAWINGS">FIG. 4</figref>, a server “S<b>4</b>” is connected to the controller “CTRL<b>1</b>” of the external disk device “ARRAY<b>1</b>” as indicated by columns <b>407</b> and <b>408</b>. As indicated by a column <b>404</b>, a path from the server “S<b>4</b>” to the controller “CTRL<b>1</b>” of the external disk device “ARRAY<b>1</b>” is “being used”. Accordingly, when a fault occurs in the controller “CTRL<b>1</b>” of the external disk device “ARRAY<b>1</b>”, the server “S<b>4</b>” cannot continue its application. Thus, the sever “S<b>4</b>” becomes an application stop server <b>1301</b>.
p-0208When no server <b>102</b> uses the faulted device, the application stop server <b>1301</b> is not present.
p-0209Subsequently, the application stop server retrieval module <b>302</b> judges whether an application stop server <b>1301</b> is present (step <b>1603</b>).
p-0210If it is judged in the step <b>1603</b> that the application stop server <b>1301</b> is not present, no server <b>102</b> needs to take over the application. In this case, the processing is finished.
p-0211On the other hand, if it is judged in the step <b>1603</b> that the application stop server <b>1301</b> is present, the application stop server retrieval module <b>302</b> requests power-OFF of the application stop server <b>1301</b> to the server power control module <b>305</b> (step <b>1604</b>).
p-0212Upon reception of the request, the server power control module <b>305</b> executes power-OFF of the application stop server <b>1301</b> (step <b>1605</b>). For example, the server power control module <b>305</b> may request the BMC <b>205</b> shown in <figref idrefs="DRAWINGS">FIG. 2</figref> to execute power-OFF via the network. The BMC <b>205</b> that has received the request turns power OFF for the server. Additionally, the server power control module <b>305</b> can request stopping or shutting-down of software operated in the server <b>102</b> before executing of the power-OFF.
p-0213The server power control module <b>305</b> confirms the power-OFF of the application stop server <b>1301</b> (step <b>1606</b>). The server power control module <b>305</b> notifies power-OFF completion to the application stop server retrieval module <b>302</b>.
p-0214Then, the processing of the server power control module <b>305</b> is finished.
p-0215Upon reception of a power-OFF completion notification, the application stop server retrieval module <b>302</b> requests the application resuming server retrieval module <b>303</b> to retrieve an application resuming server <b>1302</b> (step <b>1607</b>).
p-0216Thus, the processing of the application stop server retrieval module <b>302</b> is finished.
p-0217<figref idrefs="DRAWINGS">FIG. 17</figref> is a flowchart showing application resuming server retrieval executed by the fault recovery program <b>110</b> according to the first embodiment of this invention.
p-0218Processing shown in <figref idrefs="DRAWINGS">FIG. 17</figref> is executed by the application resuming server retrieval module <b>303</b> in the steps <b>1333</b> and <b>1334</b> of <figref idrefs="DRAWINGS">FIG. 13</figref>.
p-0219First, the application resuming server retrieval module <b>303</b> receives the identifier of the faulted device from the fault monitoring module <b>301</b> (step <b>1701</b>). This information has been transmitted in the step <b>1503</b> of <figref idrefs="DRAWINGS">FIG. 15</figref>.
p-0220Then, the application resuming server retrieval module <b>303</b> receives a retrieval request of an application resuming server <b>1302</b> from the application stop server retrieval module <b>302</b> (step <b>1702</b>). This request has been transmitted in the step <b>1607</b> of <figref idrefs="DRAWINGS">FIG. 16</figref>.
p-0221The application resuming server retrieval module <b>303</b> retrieves the application resuming server <b>13402</b> (step <b>1703</b>). This processing will be described below in detail (refer to <figref idrefs="DRAWINGS">FIG. 18</figref>).
p-0222The application resuming server retrieval module <b>303</b> refers to a result of the step <b>1703</b> to judge whether an application resuming server <b>1302</b> is present (step <b>1704</b>).
p-0223If it is judged in the step <b>1704</b> that the application resuming server <b>1302</b> is not present, no server <b>102</b> can take over the application from the application stop server <b>1301</b>. Accordingly, the processing is finished.
p-0224On the other hand, if it is judged in the step <b>1704</b> that the application resuming server <b>1302</b> is present, the application resuming server retrieval module <b>303</b> notifies an identifier of the application resuming server <b>1302</b>, a used disk identifier, and a used device to the network security control module <b>322</b> (step <b>1705</b>). The used device is a list of devices of the computer system used by the application resuming server <b>1302</b> to resume the application. For example, the used device is a combination of the devices indicated by the columns <b>405</b>, <b>406</b>, <b>407</b>, and <b>408</b> of the server information table <b>306</b> shown in <figref idrefs="DRAWINGS">FIG. 4</figref>.
p-0225Network security setting executed by the network security control module <b>322</b> that has received the notification of the step <b>1705</b> will be described below (refer to <figref idrefs="DRAWINGS">FIG. 19</figref>).
p-0226Next, the application resuming server retrieval module <b>303</b> receives a network security setting completion notification from the network security control module <b>322</b> (step <b>1706</b>). This notification has been transmitted in step <b>1905</b> of <figref idrefs="DRAWINGS">FIG. 19</figref> described below.
p-0227Then, the application resuming server retrieval module <b>303</b> refers to the external disk device information table <b>307</b> to notify an identifier of the application resuming server <b>1302</b> and a port ID of the controller <b>130</b> of the external disk device <b>103</b> used by the application resuming server <b>1302</b> for booting, to the boot setting changing module <b>304</b> (step <b>1707</b>). For example, when a controller indicted by a column <b>502</b> and disposed in the external disk device <b>103</b> indicated by a column <b>501</b> of the external disk device information table <b>307</b> is used for booting, a port ID indicated by a column <b>503</b> is notified.
p-0228The application resuming server retrieval module <b>303</b> requests the boot setting changing module <b>304</b> to change boot setting of the application resuming server <b>1302</b> (step <b>1708</b>).
p-0229Thus, the processing of the application resuming server retrieval module <b>303</b> is finished.
p-0230<figref idrefs="DRAWINGS">FIG. 18</figref> is a flowchart showing application resuming server retrieval executed by the fault recovery program <b>110</b> in detail according to the first embodiment of this invention.
p-0231To be specific, <figref idrefs="DRAWINGS">FIG. 18</figref> shows processing executed by the application resuming server retrieval module <b>303</b> in the step <b>1703</b> of <figref idrefs="DRAWINGS">FIG. 17</figref> in detail.
p-0232First, the application resuming server retrieval module <b>303</b> refers to the server information table <b>306</b> to retrieve a standing-by server <b>102</b> which does not use the faulted device (step <b>1801</b>). For example, referring to the server information table <b>306</b> of <figref idrefs="DRAWINGS">FIG. 4</figref>, a case where a fault occurs in the controller “CTRL<b>1</b>” of the external disk device “ARRAY<b>1</b>” will be described. In this case, standing-by servers “S<b>3</b>” and “S<b>6</b>” can both use the controller “CTRL<b>1</b>” of the external disk device “ARRAY<b>0</b>”. In other words, these servers do not need to use the controller “CTRL<b>1</b>” of the external disk device “ARRAY<b>1</b>”. Accordingly, the servers “S<b>3</b>” and “S<b>6</b>” correspond to the standing-by servers <b>102</b> which do not use the faulted device.
p-0233Next, the application resuming server retrieval module <b>303</b> refers to a retrieval result of the step <b>1801</b> to judge whether a standing-by server <b>102</b> not using the faulted device is present (step <b>1802</b>).
p-0234If it is judged in the step <b>1802</b> that no server satisfying the conditions of the step <b>1801</b> is present (i.e., “NO”), no server <b>102</b> that can take over the application from the application stop server <b>1301</b> is present. In this case, the processing of <figref idrefs="DRAWINGS">FIG. 18</figref> is finished.
p-0235If it is judged in the step <b>1802</b> that a server satisfying the conditions of the step <b>1801</b> is present, the application resuming server retrieval module <b>303</b> refers to the redundant path information table <b>323</b> and the server information table <b>306</b> to retrieve one or more servers <b>102</b> to be used as application resuming servers, and a device used by the server <b>102</b> (step <b>1803</b>).
p-0236The server <b>102</b> to be used as the application resuming server is specifically a server <b>102</b> connectable to the controller <b>130</b> which can access to a logical disk or a logical disk of its synchronous disk for recording the same disk image used by the application stop server <b>1301</b> for the application, among the servers <b>102</b> retrieved in the step <b>1801</b>.
p-0237The device used by the server <b>102</b> is a combination of the adaptor <b>120</b>, the NW-SW <b>104</b>, the external disk device <b>103</b>, the controller <b>130</b>, and the logical disk used by the server <b>102</b> for accessing the disk image where no fault occurs.
p-0238As an example, referring to the redundant path information table <b>323</b> (<figref idrefs="DRAWINGS">FIG. 6</figref>) and the server information table <b>306</b> (<figref idrefs="DRAWINGS">FIG. 4</figref>), a case where a fault occurs in the controller “CTRL<b>1</b>” of the external disk device “ARRAY<b>1</b>”, and the application stop server <b>1301</b> uses the disk image “D<b>4</b>” will be described.
p-0239First, the redundant path information table <b>323</b> (<figref idrefs="DRAWINGS">FIG. 6</figref>) will be referred to. The disk image “D<b>4</b>” is recorded in the disk “VOL<b>4</b>” of the external disk device “ARRAY<b>1</b>” and the disk “SVOL<b>4</b>” of the external disk device “ARRAY<b>0</b>”. The controller “CTRL<b>0</b>” of the external disk device “ARRAY<b>1</b>” provides the disk “VOL<b>4</b>” as a logical disk “LUN<b>4</b>” to the server <b>102</b>. The controller “CTRL<b>0</b>” of the external disk device “ARRAY<b>0</b>” provides the disk “SVOL<b>4</b>” as a logical disk “LUN<b>14</b>” to the server <b>102</b>.
p-0240Then, to retrieve the server <b>102</b> permitted to use the logical disk “LUN<b>4</b>” or “LUN<b>14</b>”, the server information table <b>306</b> (<figref idrefs="DRAWINGS">FIG. 4</figref>) is referred to. Here, a case where the servers “S<b>3</b>” and “S<b>6</b>” are retrieved in the step <b>1801</b> will be described.
p-0241As shown in the server information table <b>306</b>, the server “S<b>3</b>” can be connected to the controller “CTRL<b>0</b>” of the external disk device “ARRAY<b>0</b>”. In other words, the server “S<b>3</b>” can use the logical disk “LUN<b>14</b>” provided by the controller “CTRL<b>0</b>” of the external disk device “ARRAY<b>0</b>”. On the other hand, the server “S<b>6</b>” can be connected to neither of the controller “CTRL<b>0</b>” of the external disk device “ARRAY<b>1</b>” and the controller “CTRL<b>0</b>” of the external disk device “ARRAY<b>0</b>”. In other words, the server “S<b>6</b>” can use neither of the logical disks “LUN<b>4</b>” and “LUN<b>14</b>”.
p-0242In this case, as a retrieval result of the step <b>1803</b>, the server “S<b>3</b>” is obtained. In this case, used devices are the adaptor “WWN<b>3</b>” (refer to column <b>405</b>), the NW-SW “SW<b>0</b>” (refer to column <b>406</b>), the external disk device “ARRAY<b>0</b>”, and the controller “CTRL<b>0</b>”.
p-0243Then, the step <b>1803</b> is finished.
p-0244Next, the application resuming server retrieval module <b>303</b> judges which of the serves <b>102</b> has been discovered as a retrieval result of the step <b>1803</b> (step <b>1804</b>).
p-0245If it is judged in the step <b>1804</b> that no server <b>102</b> has been discovered as the retrieval result of the step <b>1803</b> (i.e., “NO”), no server <b>102</b> is present to take over the application from the application stop server <b>1301</b>. In this case, the processing of <figref idrefs="DRAWINGS">FIG. 18</figref> is finished.
p-0246On the other hand, if it is judged in the step <b>1804</b> that a certain server <b>102</b> has been discovered as the retrieval result of the step <b>1803</b>, the discovered server <b>102</b> can take over the application from the application stop server <b>1301</b>. In this case, the application resuming server retrieval module <b>303</b> decides an application resuming server <b>1301</b> and a device used by the resuming server <b>1301</b> from the resultant server <b>102</b> and used device of the step <b>1803</b> (step <b>1805</b>).
p-0247For example, when a plurality of servers <b>102</b> and when a plurality of devices used by servers <b>102</b> are discovered as a result of the step <b>1803</b>, an application resuming server <b>1301</b> and a device used by the resuming server <b>1301</b> may be decided based on specifications of the servers <b>102</b> and the used devices, position or physical conditions thereof, or priority. Alternatively, an application resuming server <b>1301</b> and a device used by the resuming server <b>1301</b> may be decided based on a policy described by a user.
p-0248After an end of the step <b>1805</b>, the processing of <figref idrefs="DRAWINGS">FIG. 18</figref> is finished.
p-0249Upon the end of the processing shown in <figref idrefs="DRAWINGS">FIG. 18</figref>, the processing of the application resuming server retrieval module <b>303</b> returns to the step <b>1704</b> of <figref idrefs="DRAWINGS">FIG. 17</figref>.
p-0250If the processing of <figref idrefs="DRAWINGS">FIG. 18</figref> is finished as a result of execution of the step <b>1805</b>, the application resuming server retrieval module <b>303</b> judges that the application resuming server is “present” in the step <b>1704</b>.
p-0251On the other hand, if the processing of <figref idrefs="DRAWINGS">FIG. 18</figref> is finished as a result of “NO” judgment in the step <b>1802</b> or <b>1804</b>, the application resuming server retrieval module <b>303</b> judges that the application resuming server is “not present” in the step <b>1704</b>.
p-0252<figref idrefs="DRAWINGS">FIG. 19</figref> is a flowchart showing network security control executed by the booth path redundancy program <b>111</b> according to the first embodiment of this invention.
p-0253Processing shown in <figref idrefs="DRAWINGS">FIG. 19</figref> is executed by the network security control module <b>322</b> in the step <b>1341</b> of <figref idrefs="DRAWINGS">FIG. 13</figref>.
p-0254First, the network security control module <b>322</b> receives an identifier of the application resuming server <b>1302</b>, a used disk identifier, and an identifier of a used device from the application resuming server retrieval module <b>303</b> (step <b>1901</b>). These pieces of information have been transmitted in the step <b>1705</b> of <figref idrefs="DRAWINGS">FIG. 17</figref>. The used device is a device of the computer system used by the application resuming server <b>1302</b> for resuming the application. For example, the used device is specified based on a combination of the devices indicated by the columns <b>405</b> to <b>408</b> of the server information table <b>306</b> shown in <figref idrefs="DRAWINGS">FIG. 4</figref>.
p-0255Next, the network security control module <b>322</b> obtains information of the adaptor ID of the application resuming server <b>1302</b>, the external disk device <b>103</b>, the controller <b>130</b>, and the logical disk among pieces of information of the used device (step <b>1902</b>).
p-0256The network security control module <b>322</b> requests the security control program of the controller <b>130</b> of the external disk device <b>103</b> obtained in the step <b>1902</b> to permit disk access with the adaptor ID and the logical disk obtained in the step <b>1902</b> (step <b>1903</b>). The security setting changing means changing of a mapping relation registered in the disk mapping table <b>1132</b> (refer to <figref idrefs="DRAWINGS">FIGS. 11 and 12</figref>).
p-0257For example, in <figref idrefs="DRAWINGS">FIG. 11</figref>, it is presumed that the ID <b>1111</b> of the adaptor <b>1110</b> disposed in the server <b>1101</b> is “WWN<b>0</b>” and the ID <b>1121</b> of the adaptor <b>1120</b> disposed in the server <b>1102</b> is “WWN<b>1</b>”. As shown in <figref idrefs="DRAWINGS">FIG. 12</figref>, the logical disk “LUN<b>0</b>” is mapped in the adaptor “WWN<b>0</b>”, and the logical disk “LUN<b>1</b>” is mapped in the adaptor “WWN<b>1</b>”. Accordingly, the server <b>1101</b> can only access the logical disk “LUN<b>0</b>” <b>1130</b>, while the server <b>1102</b> can only access the logical disk “LUN<b>1</b>” <b>1131</b>.
p-0258In this case, for example, the network security control module <b>322</b> can change a value of a column <b>1202</b> corresponding to the logical disk “LUN<b>1</b>” (in column <b>1201</b>) from “WWN<b>1</b>” to “WWN<b>0</b>” in the disk mapping table <b>1132</b> of <figref idrefs="DRAWINGS">FIG. 12</figref> by making a request to the security control program. As a result, a adaptor “WWN<b>0</b>” is mapped in the logical disk “LUN<b>1</b>”. As a result, the server <b>101</b> can access the logical disk “LUN<b>1</b>” <b>1131</b>. Accordingly, security setting is changed by changing mapping between the logical disk and the adaptor <b>120</b>.
p-0259The security control program of the external disk device <b>103</b> that has received the request of the step <b>1903</b> executes security setting changing in response to the request. Upon completion of the security setting changing, the security control program notifies the completion to the network security control module <b>322</b>.
p-0260The network security control module <b>322</b> receives the security setting changing completion notification from the security control program of the external disk device <b>103</b> (step <b>1904</b>).
p-0261Then, the network security control module <b>322</b> notifies the security setting changing completion to the application resuming server retrieval module <b>303</b> (step <b>1905</b>).
p-0262Thus, the network security control module <b>322</b> finishes the processing.
p-0263<figref idrefs="DRAWINGS">FIG. 20</figref> is a flowchart showing boot setting changing and server power control executed by the fault recovery program <b>110</b> according to the first embodiment of this invention.
p-0264Processing of <figref idrefs="DRAWINGS">FIG. 20</figref> is executed by the boot setting changing module <b>304</b>, the server power control module <b>305</b>, and the application resuming server <b>1302</b> in the steps <b>1334</b>, <b>1335</b>, and <b>1320</b> of <figref idrefs="DRAWINGS">FIG. 13</figref>.
p-0265First, the boot setting changing module <b>304</b> receives an identifier of the application resuming server <b>1302</b>, a port ID of the controller <b>130</b> of the external disk device <b>103</b> used for booting, and a boot setting changing request from the application resuming server retrieval module <b>303</b> (step <b>2001</b>). These pieces of information have been transmitted in the steps <b>1707</b> and <b>1708</b> of <figref idrefs="DRAWINGS">FIG. 17</figref>.
p-0266Next, the boot setting changing module <b>304</b> requests the server power control module <b>305</b> to turn power ON for the application resuming server <b>1302</b> (step <b>2002</b>).
p-0267The server power control module <b>305</b> that has received the request of the step <b>2002</b> instructs power-ON to the application resuming server <b>1302</b> (step <b>2003</b>). For example, the server power control module <b>305</b> transmits a power-ON request to the BMC <b>205</b> shown in <figref idrefs="DRAWINGS">FIG. 2</figref> via the network. The BMC <b>205</b> that has received the request turns power ON for the server.
p-0268Then, the server power control module <b>305</b> confirms power-ON completion of the application resuming server <b>1302</b> (step <b>2004</b>). Here, it is presumed that the application resuming server <b>1302</b> can execute network booting. For example, the NIC <b>121</b> disposed in the application resuming server <b>1302</b> supports BOOTP or PXE which is a network booting protocol. Additionally, a booting sequence of a System BIOS or EFI of the application resuming server <b>1302</b> is set to boot through network booting when power is turned ON.
p-0269Upon confirmation of the power-ON completion in the step <b>2004</b>, the boot setting changing module <b>304</b> receives a network booting request of the application resuming server <b>1302</b>, boots the application resuming server <b>1302</b> through the network, and transmits the boot setting changing program <b>340</b> to the application resuming server <b>1302</b> (step <b>2005</b>). For example, the boot setting changing module <b>304</b> is a DHCP server or the like. In this case, the boot setting changing module <b>304</b> receives the BOOTP protocol transmitted from the application resuming server <b>1302</b> via the network, and transmits the OS and the boot setting changing program necessary for booting to the application resuming server <b>1302</b> by a method of tFTP or the like. The application resuming server <b>1302</b> uses the boot setting program <b>340</b> to boot.
p-0270The application resuming server <b>1302</b> executes the boot setting changing program <b>340</b> received from the boot setting changing module <b>304</b> to change a port ID of boot setting written in the nonvolatile memory <b>203</b> of the application resuming server <b>1302</b> (step <b>2006</b>). For example, the port ID of the boot setting is a WWN of a connection destination used by a host bus adaptor (HBA) for booting when the adaptor <b>120</b> is an HBA of a fibre channel. When the adaptor <b>120</b> is a NIC of iSCSI, the port ID is an IP address or a MAC address used for booting. The port ID of the boot setting may be stored in the nonvolatile memory (not shown) of the adaptor <b>120</b>.
p-0271The boot setting changing module <b>304</b> receives a boot setting changing completion notification of the application resuming server <b>1302</b> from the boot setting changing program <b>340</b> to confirm boot setting changing completion (step <b>2007</b>).
p-0272The boot setting changing module <b>304</b> requests the server power control module <b>305</b> to reset the application stop server <b>1302</b> (step <b>2008</b>).
p-0273Then, the processing of the boot setting changing module <b>304</b> is finished.
p-0274The server power control module <b>305</b> that has received the request of the step <b>2008</b> sequentially executes power-OFF and power-ON of the application resuming server <b>1302</b> to reset the application resuming server <b>1302</b> (step <b>2009</b>). Alternatively, the boot setting changing program <b>340</b> may automatically reset it when the boot setting changing is completed.
p-0275Then, the server power control module <b>305</b> confirms resetting completion of the application resuming server <b>1302</b> (step <b>2010</b>). After the resetting execution, the application resuming server <b>1302</b> uses the disk of the external disk device <b>103</b> to boot without network booting. As methods for not executing network booting, for example, there are a method where the boot setting changing program <b>340</b> changes booting sequence setting of the system BIOS or the EFI, a method where the boot setting changing module <b>304</b> ignores the network booting request, and a method of sending a command to the BMC <b>205</b> of the application resuming server <b>1302</b> to change the booting sequence.
p-0276According to the first embodiment, the device of the computer system is divided into two. Thus, even when a certain server <b>102</b> can no longer continue the application as a result of a fault in a certain device, the fault-free server <b>102</b> can resume the application by using the fault-free device to boot. The server <b>102</b> which is unable to continue the application due to the fault is judged, the server <b>102</b> to take over the application and the device to be used by the server <b>102</b> is judged, and the processing for booting the server <b>102</b> is automatically executed by the management server <b>101</b>. Hence, it is possible to reduce a work load in the system manager.
p-0277Next, a second embodiment of this invention will be described.
p-0278The second embodiment of this invention is different from the first embodiment in that the disk synchronization program shown in <figref idrefs="DRAWINGS">FIG. 9</figref> is not present. Only differences of the second embodiment from the first embodiment will be described below.
p-0279<figref idrefs="DRAWINGS">FIG. 21</figref> is an explanatory diagram showing mirroring executed according to the second embodiment of this invention.
p-0280To be specific, <figref idrefs="DRAWINGS">FIG. 21</figref> shows a method of synchronizing contents of disks <b>2130</b> and <b>2131</b> between two different external disk devices <b>2120</b> and <b>2121</b>, and storing the same disk image D<b>0</b>.
p-0281A sever <b>102</b> of this embodiment includes a mirroring program <b>2100</b>.
p-0282When a CPU <b>2110</b> executes a writing command <b>2111</b> to write data in a disk <b>2130</b>, the mirroring program <b>2100</b> writes data in the disk <b>2130</b> and the same data in a disk <b>2131</b>. Accordingly, updating of the disk <b>2130</b> by the server <b>102</b> is always applied to the disk <b>2131</b>, and the disks <b>2130</b> and <b>2131</b> match each other in contents.
p-0283The mirroring program <b>2100</b> may be a resident program such as a demon or a service held in a memory <b>201</b> of the server <b>102</b> or a program of a driver or the like. In this case, the mirroring program <b>2100</b> is executed by the CPU <b>2110</b>. Alternatively, a function of the mirroring program <b>2100</b> may be realized by hardware provided in an adaptor <b>120</b>. In any case, when the CPU <b>2110</b> issues a data writing command in one disk <b>2130</b>, the adaptor <b>120</b> transmits a writing command in the two disks <b>2130</b> and <b>2131</b>.
p-0284Otherwise, the mirroring program <b>2100</b> (or hardware having the same function) may be present outside the server <b>102</b>. In this case, the mirroring program <b>2100</b> may create one or more pieces of copy data of data output from the adaptor <b>120</b> of the server <b>102</b>, and transmit the pieces of original data and copy data to different external disk devices <b>103</b>.
p-0285A management server <b>101</b> can control a start or a stop of synchronization of the disk <b>2130</b> or the like by controlling the mirroring program <b>2100</b> via a network.
p-0286Devices of the computer system of the second embodiment of this invention execute processing according to the sequence shown in <figref idrefs="DRAWINGS">FIG. 13</figref> as in the case of the first embodiment. However, processing of a step <b>1340</b> of the second embodiment is different from that of the first embodiment. Differences will be described below.
p-0287<figref idrefs="DRAWINGS">FIG. 22</figref> is a flowchart showing redundancy of a boot path executed by a boot redundancy program <b>111</b> according to the second embodiment of this invention.
p-0288To be specific, <figref idrefs="DRAWINGS">FIG. 22</figref> shows processing executed by a logical disk control module <b>320</b> and a synchronous disk control module <b>321</b> in the step <b>1340</b> of <figref idrefs="DRAWINGS">FIG. 13</figref> according to the second embodiment.
p-0289The processing of <figref idrefs="DRAWINGS">FIG. 22</figref> is substitution of the steps <b>1407</b> and <b>1408</b> of <figref idrefs="DRAWINGS">FIG. 14</figref> with steps <b>2201</b> and <b>2202</b>. Steps <b>1401</b> to <b>1406</b> of <figref idrefs="DRAWINGS">FIG. 22</figref> are similar to the steps <b>1401</b> to <b>1406</b> of <figref idrefs="DRAWINGS">FIG. 14</figref>, and thus description thereof will be omitted.
p-0290In the step <b>2201</b>, the synchronous disk control module <b>321</b> requests the mirroring program <b>2100</b> of the server <b>102</b> shown in <figref idrefs="DRAWINGS">FIG. 21</figref> to start synchronization of contents between the disk <b>2130</b> used by an application stop server <b>1301</b> and the synchronous disk <b>2131</b> present in another external disk device <b>2121</b>. The mirroring program <b>2100</b> that has received the request starts synchronization between the disks to notify synchronization start completion to the synchronous disk control module <b>321</b>. Then, when the CPU <b>2110</b> issues a data writing command in one disk <b>2130</b>, the adaptor <b>120</b> transmits a writing command in the two disks <b>2130</b> and <b>2131</b>.
p-0291In the step <b>2202</b>, the synchronous disk control module <b>321</b> receives the synchronization start completion notification from the mirroring program <b>2100</b> of the server <b>102</b> shown in <figref idrefs="DRAWINGS">FIG. 21</figref>.
p-0292Next, a third embodiment of this invention will be described.
p-0293The third embodiment of this invention is different from the first embodiment in that the disk synchronization program shown in <figref idrefs="DRAWINGS">FIG. 9</figref> is not present, and from the second embodiment in that the mirroring program shown in <figref idrefs="DRAWINGS">FIG. 21</figref> is not present.
p-0294<figref idrefs="DRAWINGS">FIG. 23</figref> is an explanatory diagram showing synchronous disk creation executed according to the third embodiment of this invention.
p-0295To be specific, <figref idrefs="DRAWINGS">FIG. 23</figref> shows a method of synchronizing contents of disks <b>2320</b> and <b>2321</b> between two different external disk devices <b>2310</b> and <b>2311</b> to store the same disk image D<b>0</b> according to this embodiment.
p-0296According to this embodiment, one of serves <b>102</b> of a computer system becomes a synchronous server <b>2301</b>. The synchronous server <b>2301</b> includes a synchronization program <b>2300</b>. The synchronous server <b>2301</b> may be a server <b>102</b> engaged in application or not engaged in application. The synchronous server <b>2301</b> can access disks <b>2320</b> and <b>2321</b> via an adaptor <b>2302</b> and the NW-SW <b>104</b>. The synchronization program <b>2300</b> periodically reads contents of the disk <b>2320</b>, and writes the read contents in the disk <b>2321</b> to synchronize the contents of the two disks <b>2320</b> and <b>2321</b>. As a result, when the server <b>102</b> in the computer system updates the contents of the disk <b>2320</b>, the synchronization program <b>2300</b> updates the contents of the disk <b>2321</b>.
p-0297The synchronization program <b>2300</b> may be a resident program such as a demon or a service stored in a memory <b>201</b> of the synchronous server <b>2301</b>, or a program of a driver or the like. In this case, the synchronization program <b>2300</b> is executed by a CPU <b>202</b>. Alternatively, a function of the synchronization program <b>2300</b> may be realized by hardware provided in an adaptor <b>2302</b>.
p-0298A management server <b>101</b> can control a start or a stop of disk synchronization by controlling the synchronization program <b>2300</b> via a network.
p-0299Devices of the computer system of the third embodiment of this invention execute processing according to the sequence shown in <figref idrefs="DRAWINGS">FIG. 13</figref> as in the case of the first embodiment. However, processing of a step <b>1340</b> of the third embodiment is different from that of the first embodiment. The differences will be described below.
p-0300<figref idrefs="DRAWINGS">FIG. 24</figref> is a flowchart showing redundancy of a boot path executed by a boot redundancy program <b>111</b> according to the third embodiment of this invention.
p-0301To be specific, <figref idrefs="DRAWINGS">FIG. 24</figref> shows processing executed by a logical disk control module <b>320</b> and a synchronous disk control module <b>321</b> in the step <b>1340</b> of <figref idrefs="DRAWINGS">FIG. 13</figref> according to the third embodiment.
p-0302The processing of <figref idrefs="DRAWINGS">FIG. 24</figref> is substitution of the steps <b>1407</b> and <b>1408</b> of <figref idrefs="DRAWINGS">FIG. 14</figref> with steps <b>2401</b> and <b>2402</b>. Steps <b>1401</b> to <b>1406</b> of <figref idrefs="DRAWINGS">FIG. 24</figref> are similar to the steps <b>1401</b> to <b>1406</b> of <figref idrefs="DRAWINGS">FIG. 14</figref>, and thus description thereof will be omitted.
p-0303In the step <b>2401</b>, the synchronous disk control module <b>321</b> requests the synchronization program <b>2300</b> of the synchronous server <b>2301</b> shown in <figref idrefs="DRAWINGS">FIG. 23</figref> to start synchronization of contents between the disk <b>2320</b> used by an application stop server <b>1301</b> and the synchronous disk <b>2131</b> of another external disk device <b>2311</b>. The synchronization program <b>2300</b> that has received the request starts synchronization between the disks to notify synchronization start completion to the synchronous disk control module <b>321</b>. Then, the synchronization program <b>2300</b> is executed.
p-0304In the step <b>2402</b>, the synchronous disk control module <b>321</b> receives the synchronization start completion notification from the synchronization program <b>2300</b> of the synchronous server <b>2301</b> shown in <figref idrefs="DRAWINGS">FIG. 23</figref>.
p-0305According to the second and third embodiments, even when the external disk device <b>103</b> has no function of creating a synchronous disk, this invention can be carried out by using the server <b>102</b> to create a synchronous disk.
p-0306Next, a fourth embodiment of this invention will be described.
p-0307According to the first to third embodiments, the controller <b>130</b> of the external disk device <b>103</b> includes the security control program. The security control program controls permission or inhibition of access to the disk <b>131</b> from the server <b>102</b>. However, such access permission/inhibition may be controlled by a function provided in the network. For example, the function provided in the network is a virtual LAN (VLAN) function or a zoning function.
p-0308According to the fourth embodiment of this invention, a controller <b>140</b> of a NW-SW <b>104</b> includes a security control program.
p-0309<figref idrefs="DRAWINGS">FIG. 25</figref> is an explanatory diagram showing a server information table <b>306</b> according to the fourth embodiment of this invention.
p-0310The server information table <b>306</b> shown in <figref idrefs="DRAWINGS">FIG. 25</figref> is an extension of the server information table <b>306</b> of <figref idrefs="DRAWINGS">FIG. 4</figref> to be applied to this embodiment. An extended part is a column <b>410</b>. As columns <b>401</b> to <b>408</b> are similar to the columns <b>401</b> to <b>408</b> of <figref idrefs="DRAWINGS">FIG. 4</figref>, description thereof will be omitted. Contents of the columns <b>407</b> and <b>408</b> are omitted, but contents similar to the contents of the columns <b>407</b> and <b>408</b> of <figref idrefs="DRAWINGS">FIG. 4</figref> are registered in those columns.
p-0311In the column <b>410</b>, a port number of a physical port of a connection destination is registered when an adaptor <b>120</b> identified by an adaptor ID indicated by the column <b>405</b> is connected to the physical port of a NE-SW <b>104</b> of the connection destination indicated by the column <b>406</b>.
p-0312Referring to <figref idrefs="DRAWINGS">FIG. 25</figref>, for example, an adaptor “WWN<b>0</b>” is connected to a port “<b>0</b>” of a NE-SW “SW<b>0</b>”, and an adaptor “WWN<b>1</b>” is connected to a port “<b>1</b>” of the NW-SW “SW<b>0</b>”.
p-0313<figref idrefs="DRAWINGS">FIG. 26</figref> is an explanatory diagram showing an external disk device information table <b>307</b> according to the fourth embodiment of this invention.
p-0314The external disk device information table <b>307</b> of <figref idrefs="DRAWINGS">FIG. 26</figref> is an extension of the external disk device information table <b>307</b> shown in <figref idrefs="DRAWINGS">FIG. 5</figref> to be applied to this embodiment. Extended parts are columns <b>510</b> and <b>511</b>. As columns <b>501</b> to <b>503</b> are similar to the columns <b>501</b> to <b>503</b> shown in FIG. <b>5</b>, description thereof will be omitted.
p-0315In the column <b>510</b>, an identifier of the NW-SW <b>104</b> of the connection destination of the physical port identified by a port ID indicated by the column <b>503</b> is registered.
p-0316In the column <b>511</b>, a port number of the physical port of the NW-SW <b>104</b> of the connection destination is registered when the physical port indicated by the port ID indicated by the column <b>503</b> is connected to the physical port of the NW-SW <b>104</b> indicated by the column <b>510</b>.
p-0317<figref idrefs="DRAWINGS">FIG. 27</figref> is an explanatory diagram showing security control executed by the NW-SW <b>104</b> according to the fourth embodiment of this invention.
p-0318To be specific, <figref idrefs="DRAWINGS">FIG. 27</figref> shows an outline of processing executed by a security control program <b>141</b> of the NW-SW <b>104</b> according to this embodiment. The controller <b>140</b> of the NW-SW <b>104</b> includes the security control program <b>141</b>. The security control program <b>141</b> is, for example, a program for realizing a port VLAN function, a tag VLAN function, a zoning function, or the like. The security control program <b>141</b> is stored in a memory (not shown) of the controller <b>140</b> to be executed by a CPU (not shown) of the controller <b>140</b>.
p-0319The security control program <b>141</b> can limit a combination of communicable ports by designating a number of a physical port <b>2755</b> or the like disposed in the NW-SW <b>104</b>.
p-0320In an example of <figref idrefs="DRAWINGS">FIG. 27</figref>, a port identified by an ID <b>2711</b> of an adaptor <b>2710</b> disposed in a server <b>2701</b> is connected to a port <b>5</b> (<b>2755</b>) of the NW-SW <b>104</b>. A port identified by an ID <b>2721</b> of an adaptor <b>2720</b> disposed in a server <b>2702</b> is connected to a port <b>7</b> (<b>2757</b>) of the NW-SW <b>104</b>. An external disk device <b>2703</b> is connected to a port <b>10</b> (<b>2760</b>) of the NW-SW <b>104</b>. An external disk device <b>2704</b> is connected to a port <b>11</b> (<b>2761</b>) of the NW-SW <b>104</b>.
p-0321It is presumed that the security control program <b>141</b> permits communication between the ports <b>5</b> and <b>10</b>, and communication between the ports <b>7</b> and <b>11</b>. In this case, communication can be carried out between the permitted ports. As communication is not permitted between the ports <b>5</b> and <b>11</b>, the server <b>2701</b> cannot access a disk <b>2740</b>.
p-0322The controller <b>140</b> stores a security table <b>142</b>. In the security table <b>142</b>, a combination of communicable ports of the NW-SW <b>104</b> is registered (refer to <figref idrefs="DRAWINGS">FIG. 28</figref>). The security table <b>142</b> is stored in a memory (not shown) of the controller <b>140</b>.
p-0323The security control program <b>141</b> can control a communicable combination by designating ID's <b>2711</b> and <b>2721</b> of adaptors connected to the NW-SW <b>104</b> or port ID's to <b>2731</b> and <b>2732</b> of external disk devices <b>2703</b> and <b>2704</b> to permit or inhibit communication in place of designating a combination of port numbers of the NW-SW <b>104</b>.
p-0324<figref idrefs="DRAWINGS">FIG. 28</figref> is an explanatory diagram showing the security table <b>142</b> according to the fourth embodiment of this invention.
p-0325A column <b>2801</b> indicates a group ID of security. The group ID is, for example, an ID of VLAN, an identifier of a zone in zoning, or the like.
p-0326A column <b>2802</b> indicates a combination of port numbers of the NW-SW <b>104</b> belonging to the group indicated by the column <b>2801</b>. Communication can be carried out between the port numbers belonging to the same group.
p-0327In an example of <figref idrefs="DRAWINGS">FIG. 28</figref>, in the column <b>2801</b>, “A”, “B”, and “C” are registered as security group ID's. In the column <b>2802</b>, “<b>5</b>, <b>10</b>”, “<b>7</b>, <b>1</b>”, and “<b>9</b>, <b>12</b>” are respectively registered corresponding to the security group ID's “A”, “B”, and “C”. This means that the ports <b>5</b> and <b>10</b> belong to the same security group A, the ports <b>7</b> and <b>11</b> belong to the same security group B, and the ports <b>9</b> and <b>12</b> belong to the same security group C.
p-0328The security control group <b>141</b> permits communication between the ports belonging to the same group. Thus, while communication can be carried out between the ports belonging to the same group, communication cannot be carried out between ports belonging to different groups. In other words, as shown in <figref idrefs="DRAWINGS">FIG. 27</figref>, the sever <b>2701</b> connected to the port <b>5</b> can access the logical volume “VOL<b>0</b>” of the external disk device <b>2703</b> connected to the port <b>10</b>, but not the logical volume “VOL<b>3</b>” of the external disk device <b>2704</b> connected to the port <b>11</b>.
p-0329In the column <b>2802</b>, in place of the port numbers of the NW-SW <b>104</b>, an ID of the adaptor <b>120</b> connected to the NW-SW <b>104</b> and an ID of the controller <b>130</b> of the external disk device <b>103</b> may be registered.
p-0330Devices of the computer system of the fourth embodiment of this invention execute processing according to the sequence shown in <figref idrefs="DRAWINGS">FIG. 13</figref> as in the case of the first embodiment. However, processing of a step <b>1341</b> of the fourth embodiment is different from that of the first embodiment. The differences will be described below.
p-0331<figref idrefs="DRAWINGS">FIG. 29</figref> is a flowchart showing network security control executed by a boot redundancy program <b>111</b> according to the fourth embodiment of this invention.
p-0332To be specific, <figref idrefs="DRAWINGS">FIG. 29</figref> shows processing executed by a network security control module <b>322</b> in the step <b>1341</b> of <figref idrefs="DRAWINGS">FIG. 13</figref> according to the fourth embodiment.
p-0333The processing of <figref idrefs="DRAWINGS">FIG. 29</figref> is an addition of steps <b>2901</b> to <b>2903</b> between the steps <b>1904</b> and <b>1905</b> of <figref idrefs="DRAWINGS">FIG. 19</figref>. Steps <b>1901</b> to <b>1905</b> of <figref idrefs="DRAWINGS">FIG. 29</figref> are similar to the steps <b>1901</b> to <b>1905</b> of <figref idrefs="DRAWINGS">FIG. 19</figref>, and thus description thereof will be omitted.
p-0334The network security control module <b>322</b> of this embodiment executes the step <b>2901</b> after execution of the step <b>1904</b>.
p-0335In the step <b>2901</b>, the network security control module <b>322</b> refers to the service information table <b>306</b> (of <figref idrefs="DRAWINGS">FIG. 25</figref>) and the external disk device information table <b>307</b> (of <figref idrefs="DRAWINGS">FIG. 26</figref>). The network security control module <b>322</b> obtains an identifier (registered in column <b>406</b>) of the connection destination NW-SW <b>104</b> of the adaptor port of the application resuming server <b>1302</b> and an identifier (registered in column <b>410</b>) of the physical port of the connection destination. Additionally, the network security control module <b>322</b> obtains an identifier (registered in column <b>510</b>) of the connection destination NW-SW <b>104</b> of the port disposed in the controller <b>130</b> of the external disk device <b>103</b> obtained in the step <b>1902</b>, and an identifier (registered in column <b>511</b>) of the physical port of the connection destination.
p-0336Then, in the step <b>2902</b>, the network security control module <b>322</b> requests the security control program <b>141</b> of the NW-SW <b>104</b>, which is the connection destination of the adaptor port of the application resuming server <b>1302</b> obtained in the step <b>2901</b> and the connection destination of the port disposed in the controller <b>130</b> of the external disk device <b>103</b> obtained in the step <b>1902</b>, to create a security group to which the physical port obtained in the step <b>2901</b> belongs. For example, when the identifier of the NW-SW <b>104</b> registered in the column <b>406</b> of the server information table <b>306</b> (of <figref idrefs="DRAWINGS">FIG. 25</figref>) is identical to that of the NW-SW <b>104</b> registered in the column <b>510</b> of the external disk information table <b>307</b> (of <figref idrefs="DRAWINGS">FIG. 26</figref>), the port number registered in the column <b>410</b> and the port number registered in the column <b>511</b> belong to the same security group.
p-0337The security control program <b>141</b> of the NW-SW <b>104</b> that has received the request updates the security group <b>142</b> in response to the request. Then, the security control program <b>141</b> sends a completion notification of security group creation to the network security control module <b>322</b>.
p-0338In the step <b>2903</b>, the network security control module <b>322</b> receives the security group creation completion notification from the security control program <b>141</b> of the NW-SW <b>104</b>.
p-0339Then, the step <b>1905</b> is executed to finish the processing.
p-0340According to the fourth embodiment, when the network has a VLAN function or a zoning function, this invention can also be carried out.
p-0341Next, a fifth embodiment of this invention will be described.
p-0342According to the first embodiment of this invention, the security control program <b>1103</b> of the external disk device <b>103</b> sets the disk mapping table <b>1132</b> to permit or inhibit access to the disk <b>131</b> from the server <b>102</b>. However, if the adaptor ID of the server <b>102</b> is changed, it is possible to control permission or inhibition of access of the sever <b>102</b> without changing setting of the external disk device <b>103</b> side. According to the fifth embodiment of this invention, as described above, security is controlled by changing the setting of the server <b>102</b>.
p-0343<figref idrefs="DRAWINGS">FIG. 30</figref> is an explanatory diagram showing the fault recovery program <b>110</b> and the boot path redundancy program <b>111</b> in detail according to the fifth embodiment of this invention.
p-0344As shown in <figref idrefs="DRAWINGS">FIG. 30</figref>, the fault recovery program <b>110</b> of this embodiment is the same as the fault recovery program <b>110</b> (refer to <figref idrefs="DRAWINGS">FIG. 3</figref>) of the first embodiment. The boot path redundancy program <b>111</b> of this embodiment is similar to the boot path redundancy program <b>111</b> (refer to <figref idrefs="DRAWINGS">FIG. 3</figref>) of the first embodiment except for the fact that the network security control module <b>322</b> of this embodiment includes an adaptor ID changing program <b>3000</b>. The adaptor ID changing program <b>3000</b> is a program for changing the ID of the adaptor <b>120</b> disposed in the server <b>102</b>.
p-0345Devices of the computer system of the fifth embodiment of this invention execute processing according to the sequence shown in <figref idrefs="DRAWINGS">FIG. 13</figref> as in the case of the first embodiment. However, processing of steps <b>1333</b>, <b>1334</b>, and <b>1341</b> of the fifth embodiment are different from those of the first embodiment. The differences will be described below.
p-0346<figref idrefs="DRAWINGS">FIG. 31</figref> is a flowchart showing application resuming server retrieval executed by the fault recovery program <b>110</b> according to the fifth embodiment of this invention.
p-0347Processing shown in <figref idrefs="DRAWINGS">FIG. 31</figref> is processing executed by the application resuming server retrieval module <b>303</b> of this embodiment in the steps <b>1333</b> and <b>1334</b> of <figref idrefs="DRAWINGS">FIG. 13</figref>.
p-0348The processing of <figref idrefs="DRAWINGS">FIG. 31</figref> is substitution of the step <b>1705</b> of <figref idrefs="DRAWINGS">FIG. 17</figref> with a step <b>3100</b>. Steps <b>1701</b> to <b>1704</b> and steps <b>1706</b> to <b>1708</b> of <figref idrefs="DRAWINGS">FIG. 31</figref> are similar to the steps <b>1701</b> to <b>1704</b> and steps <b>1706</b> to <b>1708</b> of <figref idrefs="DRAWINGS">FIG. 17</figref>, and thus description thereof will be omitted.
p-0349In the step <b>3100</b>, the application resuming server retrieval module <b>303</b> notifies an identifier of the application resuming server <b>1302</b>, an ID of the adaptor <b>120</b> of the application resuming server <b>1302</b>, an identifier of the application stop server <b>1301</b>, and an ID of the adaptor of the application stop server <b>1301</b> to the network security control module <b>322</b>.
p-0350<figref idrefs="DRAWINGS">FIG. 32</figref> is a flowchart showing network security control executed by the boot path redundancy program <b>111</b> according to the fifth embodiment of this invention.
p-0351Processing shown in <figref idrefs="DRAWINGS">FIG. 32</figref> is processing executed by the network security control module <b>322</b>, the server power control module <b>305</b>, and the application resuming server <b>1302</b> of this embodiment in the step <b>1341</b> of <figref idrefs="DRAWINGS">FIG. 13</figref>.
p-0352First, the network security control module <b>322</b> receives an identifier of the application resuming server <b>1302</b>, an ID of the adaptor of the application resuming server <b>1302</b>, an identifier of the application stop server <b>1301</b>, and an ID of the adaptor of the application stop server <b>1301</b> from the application resuming server retrieval module <b>303</b> (step <b>3201</b>).
p-0353Then, the network security control module <b>322</b> requests the server power control module <b>305</b> to turn power ON for the application resuming server <b>1302</b> (step <b>3202</b>).
p-0354The server power control module <b>305</b> that has received the request in the step <b>3202</b> turns power ON for the application resuming server <b>1302</b> (step <b>3203</b>).
p-0355Then, the server power control module <b>305</b> confirms power-ON completion of the application resuming server <b>1302</b> (step <b>3204</b>). The application resuming server <b>1302</b> is, for example, set to boot through the network by a method of PXE or the like.
p-0356Then, the network security control module <b>322</b> boots the application resuming server <b>1302</b> through the network, and transmits the adaptor ID changing program <b>3000</b> to the application resuming server <b>1302</b> (step <b>3205</b>). In this case, for example, the network security control module <b>322</b> is operating a program corresponding to network booting of DHCP or the like, and can send the adaptor ID changing program <b>3000</b> to the application resuming server <b>1302</b> by a tftp method or the like.
p-0357The application resuming server <b>1302</b> executes the received adaptor ID changing program <b>3000</b> (step <b>3206</b>). As a result, the ID of the adaptor <b>120</b> of the application resuming server <b>1302</b> obtained in the step <b>3201</b> is rewritten with an ID of the adaptor <b>120</b> of the application stop server <b>1301</b>. For example, the adaptor <b>120</b> itself may include an ID rewriting function, and the adaptor ID changing program <b>3000</b> may use this function to rewrite the ID. Alternatively, the adaptor ID changing program <b>3000</b> may directly rewrite a file or data storing the ID.
p-0358Then, the network security control module <b>322</b> confirms boot setting changing completion of the application resuming server <b>1302</b> (step <b>3207</b>).
p-0359Then, the network security control module <b>322</b> notifies the security setting changing completion to the application resuming retrieval module <b>303</b> (step <b>3208</b>).
p-0360Then, the processing of <figref idrefs="DRAWINGS">FIG. 32</figref> is finished.
p-0361According to the fifth embodiment of this invention, the invention can be carried out without changing the security setting of the network side or the external disk device <b>103</b> side.
p-0362According to this embodiment of this invention, reliability of the computer system is improved. Further, as the servers can access the same disk image via a plurality of independent networks, the servers that use the networks can realize parallel data processing. As a result, there is an effect of achieving a high speed for processing of the computer system.
p-0363While the present invention has been described in detail and pictorially in the accompanying drawings, the present invention is not limited to such detail but covers various obvious modifications and equivalent arrangements, which fall within the purview of the appended claims.
Contents5
34 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17 Sheet 18 Sheet 19 Sheet 20 Sheet 21 Sheet 22 Sheet 23 Sheet 24 Sheet 25 Sheet 26 Sheet 27 Sheet 28 Sheet 29 Sheet 30 Sheet 31 Sheet 32 Sheet 33 Sheet 34
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US2009070789A1 | Cited by | United States of America | Pre-grant |
| US8788636B2 | Cited by | United States of America | Search report |
| US8176498B2 | Cited by | United States of America | Search report |
| US7966515B2 | Cited by | United States of America | Search report |
| US2010023591A1 | Cited by | United States of America | Pre-grant |
| US8407514B2 | Cited by | United States of America | Search report |
| US7877625B2 | Cited by | United States of America | Search report |
| US8364809B2 | Cited by | United States of America | Applicant |
| US8516296B2 | Cited by | United States of America | Applicant |
| US10235254B2 | Cited by | United States of America | Applicant |
| US9342416B2 | Cited by | United States of America | Search report |
| US2015154088A1 | Cited by | United States of America | Pre-grant |
| US2011225449A1 | Cited by | United States of America | Pre-grant |
| US2011099416A1 | Cited by | United States of America | Pre-grant |
| US7616631B2 | Cited by | United States of America | Search report |
| US2009265493A1 | Cited by | United States of America | Pre-grant |
| US2011060941A1 | Cited by | United States of America | Pre-grant |
| US2004032834A1 | Cited by | United States of America | Pre-grant |
| US2009282142A1 | Cited by | United States of America | Pre-grant |
| JP2000047894A | Cites | Japan | Applicant |
| JP2002215474A | Cites | Japan | Applicant |
| US2003217310A1 | Cites | United States of America | Search report |
| US2005144505A1 | Cites | United States of America | Search report |
| US2006106819A1 | Cites | United States of America | Search report |
| US5633999A | Cites | United States of America | Search report |
| US6594775B1 | Cites | United States of America | Search report |
| US6718481B1 | Cites | United States of America | Search report |
| US7103807B2 | Cites | United States of America | Search report |
| US7216258B2 | Cites | United States of America | Search report |
| US7240234B2 | Cites | United States of America | Search report |
| US7266758B2 | Cites | United States of America | Search report |
| US7401254B2 | Cites | United States of America | Search report |
| US7418564B2 | Cites | United States of America | Search report |
4 priority claims, no other members on record
Priority claims4
| Document | Office | Kind | Date |
|---|---|---|---|
| 2006117822 | Japan | A | |
| 2006117822 | Japan | A | |
| 2006117822 | – | – | – |
| JP20060117822 | – | – | – |
26 transactions on the USPTO file
Allowed without a rejection on record.
- Non-final rejections
- 0
- Final rejections
- 0
- RCEs
- 0
- Appeals
- 0
Over time
Point at a mark for the transactionTransactions
| Event | Code | |
|---|---|---|
| Recordation of Patent Grant MailedPGM/ | PGM/ | |
| Patent Issue Date Used in PTA CalculationAllowedPTAC | PTAC | |
| Issue Notification MailedAllowedWPIR | WPIR | |
| Dispatch to FDCD1935 | D1935 | |
| Application Is Considered Ready for IssuePILS | PILS | |
| Issue Fee Payment VerifiedN084 | N084 | |
| Issue Fee Payment ReceivedIFEE | IFEE | |
| Mail Notice of AllowanceAllowedMN/=. | MN/=. | |
| Notice of Allowance Data Verification CompletedAllowedN/=. | N/=. | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| PG-Pub Issue NotificationPG-ISSUE | PG-ISSUE | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Transfer Inquiry to GAUTI1050 | TI1050 | |
| IFW TSS Processing by Tech Center CompleteTSSCOMP | TSSCOMP | |
| Application Dispatched from OIPEOIPE | OIPE | |
| Application Is Now CompleteCOMP | COMP | |
| Additional Application Filing FeesADDFLFEE | ADDFLFEE | |
| A statement by one or more inventors satisfying the requirement under 35 USC 115, Oath of the ApplicOATHDECL | OATHDECL | |
| Notice Mailed--Application Incomplete--Filing Date AssignedINCD | INCD | |
| Cleared by OIPE CSRL194 | L194 | |
| IFW Scan & PACR Auto Security ReviewSCAN | SCAN | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Request for Foreign Priority (Priority Papers May Be Included)RQPR | RQPR | |
| Information Disclosure Statement (IDS) FiledM844 | M844 | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Initial Exam Team nnIEXX | IEXX |
9 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Lapsed due to failure to pay maintenance feeLapsedFP | FP | |
| Lapse for failure to pay maintenance feesLapsedPATENT EXPIRED FOR FAILURE TO PAY MAINTENANCE FEES (ORIGINAL EVENT CODE: EXP.); ENTITY STATUS OF PATENT OWNER: LARGE ENTITYLAPS | LAPS | |
| Information on status: patent discontinuationPATENT EXPIRED DUE TO NONPAYMENT OF MAINTENANCE FEES UNDER 37 CFR 1.362STCH | STCH | |
| Fee payment procedureMAINTENANCE FEE REMINDER MAILED (ORIGINAL EVENT CODE: REM.); ENTITY STATUS OF PATENT OWNER: LARGE ENTITYFEPP | FEPP | |
| Fee paymentFPAY | FPAY | |
| Fee paymentFPAY | FPAY | |
| Fee payment procedurePAYOR NUMBER ASSIGNED (ORIGINAL EVENT CODE: ASPN); ENTITY STATUS OF PATENT OWNER: LARGE ENTITYFEPP | FEPP | |
| Information on status: patent grantGrantedPATENTED CASESTCF | STCF | |
| AssignmentAS | AS |
Numbers
- Publication, DOCDB
- 7533288
- Publication, EPODOC
- US7533288
- Application
- 11580415
- Application, DOCDB
- 58041506
- Application, EPODOC
- US20060580415
Titles
- English
- Method of achieving high reliability of network boot computer system
Patent term adjustment
- A delay
- +393 daysthe office missed an examination deadline
- Net adjustment
- 393 days
Classification
- CPC, 4
- G06F11/0793
- G06F9/4406
- G06F11/2028
- G06F11/2046
- IPC, 1
- G06F11 00
- USPC, 1
- 714004400